CVE-2023-45757
Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page.
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can send http request to bRPC server with rpcz enabled can inject arbitrary XSS code to the builtin rpcz page. Solution (choose one of three): 1. upgrade to bRPC > 1.6.0, download link: https://dist.apache.org/repos/dist/release/brpc/1.6.1/ 2. If you are using an old version of bRPC and hard to upgrade, you can apply this patch: https://github.com/apache/brpc/pull/2411 3. disable rpcz feature
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- apache/brpc
- Source
- security@apache.org
References
- http://www.openwall.com/lists/oss-security/2023/10/16/8Mailing List, Third Party Advisory
- https://lists.apache.org/thread/6syxv32fqgl30brfpttrk4rfsb983hl4Mailing List, Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/10/16/8Mailing List, Third Party Advisory
- https://lists.apache.org/thread/6syxv32fqgl30brfpttrk4rfsb983hl4Mailing List, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.