VDB
CVE-2021-36155
CVE-2021-36155
PUBLISHED
CVSS 7.5 HIGH
LengthPrefixedMessageReader in gRPC Swift 1.1.0 and earlier allocates buffers of arbitrary length, which allows remote attackers to cause uncontrolled resource consumption and deny service.
EPSS 2.08% · 80.6th percentile
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
2.08%
80.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | grpc/grpc-swift | 0 |
| n/a | n/a | n/a |
| linuxfoundation | grpc_swift | 1.1.0, 1.1.1, 1.0.0 |
Timeline
- Jul 9, 2021 CVE Published
- Jul 10, 2021 EPSS Score
- Sep 8, 2021 EPSS Score
- Nov 7, 2021 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 7, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 7, 2022 EPSS Score
- Jul 6, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Jan 3, 2023 EPSS Score
- Mar 4, 2023 EPSS Score
References
- https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=35303 url
- https://github.com/grpc/grpc-swift/security/advisories/GHSA-rxmj-hg9v-vp3p url
- https://nvd.nist.gov/vuln/detail/CVE-2021-36155 advisory
- https://github.com/grpc/grpc-swift package
- https://github.com/grpc/grpc-swift/releases/tag/1.2.0 url
- https://github.com/grpc/grpc-swift/releases technical