Uncontrolled Memory Allocation in grpc-node - CVE-2024-37168
Published: October 11, 2024
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due there are two separate code paths in which memory can be allocated per message in excess of the `grpc.max_receive_message_length` channel option. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Affected software
Answer Retrieval for Watson Discovery On Prem
IBM Cloud Pak for Watson AIOps
Voice Gateway
App Connect Enterprise Certified Container
IBM Watson Assistant for IBM Cloud Pak for Data
IBM Maximo Application Suite
How to mitigate CVE-2024-37168
Answer Retrieval for Watson Discovery On Prem - update to 2.18.0
Voice Gateway - addressed in versions 1.0.8.13, 1.0.8.21
App Connect Enterprise Certified Container - addressed in versions 5.0.20, 12.2.0
IBM Cloud Pak for Watson AIOps - update to 4.7.0
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.3
IBM Maximo Application Suite - addressed in versions 8.10.17, 8.11.14, 9.0.3
External References
- https://github.com/grpc/grpc-node/security/advisories/GHSA-7v5v-9h63-cj86
- https://github.com/grpc/grpc-node/commit/08b0422dae56467ecae1007e899efe66a8c4a650
- https://github.com/grpc/grpc-node/commit/674f4e351a619fd4532f84ae6dff96b8ee4e1ed3
- https://github.com/grpc/grpc-node/commit/a8a020339c7eab1347a343a512ad17a4aea4bfdb
Related Security Bulletins
- Uncontrolled memory allocation in grpc/grpc-js
- IBM Maximo Application Suite update for grpc-js-1.8.21.tgz
- IBM Watson Assistant for IBM Cloud Pak for Data update for gRPC on Node.js
- Multiple vulnerabilities in IBM Cloud Pak for AIOps
- Multiple vulnerabilities in IBM Voice Gateway
- Multiple vulnerabilities in IBM App Connect Enterprise Certified Container
- Multiple vulnerabilities in IBM Answer Retrieval for Watson Discovery