Multiple security vulnerabilities have been identified and addressed in grpc-go affecting the xDS RBAC authorization engine (internal/xds/rbac) and the HTTP/2 transport server implementation (internal/transport). These vulnerabilities could result in:
Metadata or RequestedServerName fields.NOT rules around unsupported fields.What kind of vulnerability is it? Who is impacted?
Metadata & RequestedServerName matcherspermission and principal rules (specifically Metadata and RequestedServerName) were silently ignored and treated as no-ops.
NOT rules (Permission_NotRule / Principal_NotId) or multi-condition OR/AND rules, silently dropping them changed the boolean logic flow of the authorization engine.As a result, policy evaluation decisions could fail open, allowing unauthorized clients to access protected gRPC services or resources.
SETTINGS ACKs or server-initiated RST_STREAMs.When a client initiated a rapid flood of stream creation (HEADERS) immediately...
1.82.1Exploitability
AV:NAC:LAT:NPR:NUI:NVulnerable System
VC:NVI:HVA:HSubsequent System
SC:NSI:NSA:N8.8/CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N