@grpc/grpc-js-xds@1.3.2

Plugin for @grpc/grpc-js. Adds the xds:// URL scheme and associated features.

  • latest version

    1.14.1

  • latest non vulnerable version

  • first published

    5 years ago

  • latest version published

    16 days ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the @grpc/grpc-js-xds package. This does not include vulnerabilities belonging to this package’s dependencies.

    Fix vulnerabilities automatically

    Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Partial String Comparison

    @grpc/grpc-js-xds is a Plugin for @grpc/grpc-js. Adds the xds:// URL scheme and associated features.

    Affected versions of this package are vulnerable to Partial String Comparison via the PathExactValueMatcher.apply method in matcher.ts, where the case-insensitive exact path match incorrectly uses a prefix match (startsWith) instead of a strict equality check. When RBAC rules are configured to enforce authentication based on exact path (method name) matching, an attacker can bypass those rules by appending arbitrary suffixes to a permitted path, causing requests that should be denied to be incorrectly allowed.

    How to fix Partial String Comparison?

    Upgrade @grpc/grpc-js-xds to version 1.13.1, 1.14.1 or higher.

    <1.13.1>=1.14.0 <1.14.1