VYPR

apk package

chainguard/wavefront-proxy

pkg:apk/chainguard/wavefront-proxy

Vulnerabilities (62)

  • CVE-2023-32731HigJun 9, 2023
    affected < 13.4-r1fixed 13.4-r1

    When gRPC HTTP2 stack raised a header size exceeded error, it skipped parsing the rest of the HPACK frame. This caused any HPACK table mutations to also be skipped, resulting in a desynchronization of HPACK tables between sender and receiver. If leveraged, say, between a proxy an

  • CVE-2023-1428HigJun 9, 2023
    affected < 13.4-r1fixed 13.4-r1

    There exists an vulnerability causing an abort() to be called in gRPC.  The following headers cause gRPC's C++ implementation to abort() when called via http2: te: x (x != trailers) :scheme: x (x != http, https) grpclb_client_stats: x (x == anything) On top of sending one of

Page 4 of 4