GHSA-f596-whhp-79r4: Low severity npm/@grpc/grpc-js vulnerability
Impact If an application method handler crashes, the error message is included in the status message sent to the client. This can leak to the client any sensitive data that may be included in the error message. This impacts anyone using @grpc/grpc-js to run servers.
Patches This vulnerability is fixed in 1.13.6 and 1.14.5.
Workarounds This can be avoided by using a top-level error handler in method handlers to strip out sensitive error information.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.5 - Upgrade
Upgrade
npm/@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.6 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.6 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.5 - Configuration
Use a top-level error handler in method handlers to strip sensitive error information from errors returned to clients.
@grpc/grpc-js server method handlers top-level error handler = strip sensitive error information
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Any application using @grpc/grpc-js to run gRPC servers is impacted. The issue concerns error messages returned when an application method handler crashes.
What does an attacker need to do to obtain sensitive information?
An attacker would need to cause an application method handler to crash and receive the resulting status message. Sensitive data is exposed only if it is included in the handler's error message.
Are fixed versions available?
Yes. The issue is fixed in @grpc/grpc-js versions 1.13.6 and 1.14.5.
What can be done if upgrading is not immediately possible?
Use a top-level error handler in method handlers that strips sensitive information from errors before status messages are sent to clients.