@grpc/grpc-js is vulnerable to Information Disclosure
37
Low Risk
When an application method handler throws inside @grpc/grpc-js, the server includes the thrown error's message text in the gRPC status details sent back to the client. Any sensitive data an application puts in an exception message is exposed to remote callers by default. The patch replaces the forwarded message with a generic Unknown error detail and only sends the original message when the new GRPC_NODE_DEBUG_SEND_ERROR_DETAILS environment variable is enabled.
You are affected if you are using a version that falls within the vulnerable range and a method handler in your service can throw an error whose message contains sensitive information.
@grpc/grpc-js is vulnerable to Information Disclosure in versions 0.0.1 - 1.13.5 and 1.14.0 - 1.14.4.
Upgrade the @grpc/grpc-js library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.