Intel

AIKIDO-2024-10010

@grpc/grpc-js is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Mar 22, 2024

94

Critical Risk

This Affects:

js@grpc/grpc-js
1.10.2 - 1.10.2
Fixed in 1.10.3
Are you affected? Scan for Free

TL;DR

The affected version of grpc-js contains a flaw that can result in dropped requests.

Who does this affect?

You are affected only if you use this specific version of grpc-js.

Background info

@grpc/grpc-js is vulnerable to Denial of Service (DoS) in versions 1.10.2 - 1.10.2.

How to fix this

You can either downgrade to an earlier version or upgrade to a newer version of grpc-js.

Reporter

Qover