spring-grpc-core is vulnerable to Improper Isolation or Compartmentalization
42
Medium Risk
Affected versions of Spring gRPC are vulnerable to Improper Isolation or Compartmentalization. When an authenticated user is denied access to a gRPC method, their authenticated identity remains bound to the gRPC worker thread and can be inherited by a subsequent unauthenticated request on the same thread. This may allow the subsequent user to gain escalated permissions.
You are affected if using a vulnerable version.
spring-grpc-core is vulnerable to Improper Isolation or Compartmentalization in versions 0.0.1 - 1.0.2.
Upgrade the org.springframework.grpc:spring-grpc-core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant