PT-2026-102346 · Npm · @Grpc/Grpc-Js-Xds+1
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
@grpc/grpc-js versions prior to 1.13.6
@grpc/grpc-js versions prior to 1.14.5
Description
The
getAuthContext() function fails to distinguish between authorized and unauthorized peer certificates when server credentials have requireClientCertificate set to false. This can lead to improper authentication if applications rely on the returned authentication context, treating unauthorized certificates as authorized. This condition can also occur in @grpc/grpc-js-xds when Role-Based Access Control (RBAC) authentication is enabled in affected configurations.Recommendations
Update @grpc/grpc-js to version 1.13.6.
Update @grpc/grpc-js to version 1.14.5.
Exploit
Fix
Improper Certificate Validation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Grpc/Grpc-Js
@Grpc/Grpc-Js-Xds