PT-2026-102334 · Npm · @Grpc/Grpc-Js
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@grpc/grpc-js versions prior to 1.13.1
@grpc/grpc-js versions prior to 1.14.1
Description
When case-insensitive matching is enabled, the Role-Based Access Control (RBAC) exact path matcher performs a prefix comparison instead of an equality comparison for method names. If one service method name is a prefix of another and both have different access rules, a request for the longer method may incorrectly match the rule of the shorter method, leading to improper authorization.
Recommendations
Update to version 1.13.1.
Update to version 1.14.1.
Enable case-sensitive path matching to avoid this issue.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
@Grpc/Grpc-Js