The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/grpc/grpc-go/internal/xds/httpfilter/rbac to version 1.83.1 or higher.
Affected versions of this package are vulnerable to Improper Handling of Case Sensitivity in the xDS RBAC HTTP filter, which unconditionally lowercases incoming metadata keys so a header matcher configured with uppercase letters, such as X-Role, never matches. An attacker can reach traffic that an RBAC policy was meant to deny, since the rule evaluates as a non-match and fails open, and can also smuggle reserved grpc--prefixed headers such as Grpc-Status past the case-sensitive gRFC A41 validation by altering their casing. This applies only where an operator has defined xDS RBAC policies with header matchers, and the policy bypass depends on those matchers using mixed-case header names.