GHSA-g76f-gjfx-4rpr

Suggest an improvement
Source
https://github.com/advisories/GHSA-g76f-gjfx-4rpr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/09/GHSA-g76f-gjfx-4rpr/GHSA-g76f-gjfx-4rpr.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g76f-gjfx-4rpr
Aliases
Published
2024-09-04T18:30:58Z
Modified
2024-09-04T20:57:34.532255Z
Severity
  • 5.8 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator
Summary
Vertx gRPC server does not limit the maximum message size
Details

In Eclipse Vert.x version 4.3.0 to 4.5.9, the gRPC server does not limit the maximum length of message payload (Maven GAV: io.vertx:vertx-grpc-server and io.vertx:vertx-grpc-client). 

This is fixed in the 4.5.10 version. 

Note this does not affect the Vert.x gRPC server based grpc-java and Netty libraries (Maven GAV: io.vertx:vertx-grpc)

Database specific
{
    "nvd_published_at": "2024-09-04T16:15:09Z",
    "cwe_ids": [
        "CWE-770"
    ],
    "severity": "MODERATE",
    "github_reviewed": true,
    "github_reviewed_at": "2024-09-04T20:32:19Z"
}
References

Affected packages

Maven / io.vertx:vertx-grpc-server

Package

Name
io.vertx:vertx-grpc-server
View open source insights on deps.dev
Purl
pkg:maven/io.vertx/vertx-grpc-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.5.10

Affected versions

4.*

4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9

Maven / io.vertx:vertx-grpc-client

Package

Name
io.vertx:vertx-grpc-client
View open source insights on deps.dev
Purl
pkg:maven/io.vertx/vertx-grpc-client

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.3.0
Fixed
4.5.10

Affected versions

4.*

4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.4.0
4.4.1
4.4.2
4.4.3
4.4.4
4.4.5
4.4.6
4.4.7
4.4.8
4.4.9
4.5.0
4.5.1
4.5.2
4.5.3
4.5.4
4.5.5
4.5.6
4.5.7
4.5.8
4.5.9