GHSA-m9gg-hp2v-232j: High severity npm/@grpc/grpc-js vulnerability
Impact When server credentials are created with the requireClientCertificate option set to false, getAuthContext does not distinguish between authorized and unauthorized certificates in its return value. This can create improper authentication vulnerabilities for @grpc/grpc-js users who use the result of getAuthContext for authentication.
In particular, @grpc/grpc-js-xds can both set the requireClientCertificate option to false and use the return value of getAuthContext for RBAC authentication in some configurations.
Patches
This vulenrability is fixed in 1.13.6 and 1.14.5.
Workarounds @grpc/grpc-js users using getAuthContext this way can avoid this problem by setting requireClientCertificate to true. @grpc/grpc-js-xds users using RBAC can avoid this by setting the requireclientcertificate field to true in the DownstreamTlsContext in the xDS configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.5 - Upgrade
Upgrade
npm/@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.6 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.13.6 - Upgrade
Upgrade
@grpc/grpc-jsto a version that resolves this vulnerability.Fixed in 1.14.5 - Configuration
Set require_client_certificate to true in the DownstreamTlsContext for @grpc/grpc-js-xds users using RBAC, or set requireClientCertificate to true when @grpc/grpc-js users use getAuthContext for authentication.
@grpc/grpc-js-xds and @grpc/grpc-js require_client_certificate / requireClientCertificate = true
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
Deployments are exposed when server credentials set requireClientCertificate to false and application authentication relies on the return value of getAuthContext. Certain @grpc/grpc-js-xds configurations are also affected when they use RBAC authentication and can set this option to false.
What does an attacker need to exploit the issue?
An attacker needs to present an unauthorized client certificate to a server whose authentication decision uses getAuthContext while requireClientCertificate is false. In that configuration, getAuthContext does not distinguish authorized certificates from unauthorized ones.
How can this be mitigated if an upgrade cannot be applied immediately?
For @grpc/grpc-js, set requireClientCertificate to true where getAuthContext is used for authentication. For @grpc/grpc-js-xds deployments using RBAC, set require_client_certificate to true in the xDS DownstreamTlsContext configuration.
Which versions contain the fix?
The issue is fixed in versions 1.13.6 and 1.14.5.