Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-32731
HistoryJun 09, 2023 - 12:00 a.m.

CVE-2023-32731

2023-06-0900:00:00
ubuntu.com
ubuntu.com
30
grpc
http2
hpack
information leak
data exfiltration

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

56.4%

When gRPC HTTP2 stack raised a header size exceeded error, it skipped
parsing the rest of the HPACK frame. This caused any HPACK table mutations
to also be skipped, resulting in a desynchronization of HPACK tables
between sender and receiver. If leveraged, say, between a proxy and a
backend, this could lead to requests from the proxy being interpreted as
containing headers from different proxy clients - leading to an information
leak that can be used for privilege escalation or data exfiltration. We
recommend upgrading beyond the commit contained in
https://github.com/grpc/grpc/pull/33005
https://github.com/grpc/grpc/pull/33005

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.002 Low

EPSS

Percentile

56.4%