GHSA-88h9-xgvx-hvf2: Medium severity npm/@grpc/grpc-js-xds vulnerability
Impact When using RBAC to apply authentication rules, the exact path (method name) matcher applies a prefix match instead of an exact match for case-insensitive matches. As a result, if a service has a method with a name that is a prefix of the name of a different method, and they have different access rules, and case-insensitive matching is used, this bug can cause improper authentication.
Patches
This vulnerability is fixed in 1.13.1 and 1.14.1.
Workarounds This problem can be avoided by enabling case-sensitive path matching.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@grpc/grpc-js-xdsto a version that resolves this vulnerability.Fixed in 1.14.1 - Upgrade
Upgrade
npm/@grpc/grpc-js-xdsto a version that resolves this vulnerability.Fixed in 1.13.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.13.1 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 1.14.1 - Configuration
Enable case-sensitive path matching to avoid improper authentication caused by case-insensitive prefix matching.
case-sensitive path matching = enabled
Event History
Frequently Asked Questions
Which deployments are affected by this issue?
Deployments using RBAC authentication rules with case-insensitive exact path (method name) matching are affected when one service method name is a prefix of another method name and the two methods have different access rules.
What does an attacker need to exploit the vulnerability?
An attacker must be able to send a request to a method whose name extends a differently authorized method name. Exploitation depends on the affected service having the relevant prefix-named methods and case-insensitive matching enabled.
Is there a mitigation if upgrading is not immediately possible?
Enable case-sensitive path matching. This avoids the incorrect prefix behavior in case-insensitive matching.
Which versions contain fixes?
The issue is fixed in versions 1.13.1 and 1.14.1.