Vulnerability GHSA-pp75-xfpw-37g9

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
5 years ago
May 10, 2021 at 07:16 PM UTC
Prototype pollution in grpc and @grpc/grpc-js
0.5.0 - 1.24.3
0.5.0 - 1.24.3

Summary

Prototype pollution in grpc and @grpc/grpc-js

Details

"The package grpc before 1.24.4 and the package @grpc/grpc-js before 1.1.8 are vulnerable to Prototype Pollution via loadPackageDefinition."

Related Vulnerabilities

Other vulnerabilities affecting the same packages

High Risk
2 hours ago
@grpc/grpc-js: In certain configurations, getAuthContext can return unauthorized certificates as though they were authorized
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-m9gg-hp2v-232j
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-m9gg-hp2v-232j
Low Risk
2 hours ago
@grpc/grpc-js: The server transmits some error messages thrown by method handlers to the client in status messages
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-f596-whhp-79r4
0.1.0 - 1.13.5 and 1.14.0 - 1.14.4 GHSA-f596-whhp-79r4
High Risk
3 months ago
@grpc/grpc-js: A malformed request can cause a server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-5375-pq7m-f5r2
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-5375-pq7m-f5r2
High Risk
3 months ago
@grpc/grpc-js: An incoming malformed compressed message can cause a client or server crash
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-99f4-grh7-6pcq
0.1.0 - 1.9.15 and 1.10.0 - 1.10.11 and 1.11.0 - 1.11.3 and 1.12.0 - 1.12.6 and 1.13.0 - 1.13.4 and 1.14.0 - 1.14.3 GHSA-99f4-grh7-6pcq
Medium Risk
2 years ago
@grpc/grpc-js can allocate memory for incoming messages well above configured limits
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8 GHSA-7v5v-9h63-cj86
0.1.0 - 1.8.21 and 1.9.0 - 1.9.14 and 1.10.0 - 1.10.8 GHSA-7v5v-9h63-cj86
View all vulnerabilities for these packages

Impacted packages

Timeline

Published
5 years ago
May 10, 2021 at 07:16 PM UTC
Fixed (1.1.8)
5 years ago
October 28, 2020 at 08:33 PM UTC
Fixed (1.24.4)
5 years ago
November 10, 2020 at 10:55 PM UTC
Last Modified
1 year ago
January 14, 2025 at 08:57 AM UTC