grpc-ecosystem / grpc-health-probe

A command-line tool to perform health-checks for gRPC applications in Kubernetes and elsewhere

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

CVE issue

limbuster opened this issue · comments

Can we make a new release to address the following CVE? The updated version of the affected package has already been merged to master branch.

Affected package: google.golang.org/grpc
Vulnerability: GHSA-m425-mq94-257g | gRPC-Go HTTP/2 Rapid Reset vulnerability

+1 Release Urgently Required.

CVE-2023-44487 was already

  • partially fixed related CVE-2023-44487 in release v0.4.21 via #160 and
  • grpc fixed on master via unreleased #166.

It seems it just needs a release.

@stefanb Yes, just needs a new release.

@stefanb yes, we just need a new release with the updated google.golang.org/grpc

@ahmetb, please review above and if you agree create a new release v0.4.22 at:
https://github.com/grpc-ecosystem/grpc-health-probe/releases/new

I don't think this impacts grpc clients? This tool is not a grpc server either so I don't think it's applicable. It's quite laborious to keep releasing updates for issues not really impacting the tool.

Tagged v0.4.22.

I don't think this impacts grpc clients? This tool is not a grpc server either so I don't think it's applicable. It's quite laborious to keep releasing updates for issues not really impacting the tool.

Indeed. But people are getting warnings (false positive in this case) from various tools and want to silence them.