CVE-2023-31039

Severity
9.8CRITICAL
EPSS
0.4%
top 39.39%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 8
Latest updateJul 6

Description

Security vulnerability in Apache bRPC = 1.5.0, download link: https://dist.apache.org/repos/dist/release/brpc/1.5.0/ https://dist.apache.org/repos/dist/release/brpc/1.5.0/ 2. If you are using an old version of bRPC and hard to upgrade, you can apply this patch: https://github.com/apache/brpc/pull/2218 https://github.com/apache/brpc/pull/2218

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

NVDapache/brpc0.9.01.5.0
CVEListV5apache_software_foundation/apache_brpc0.9.01.5.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-8fwm-xh4w-q393: Security vulnerability in Apache bRPC = 12023-07-06
CVEList
Apache bRPC: ServerOptions.pid_file may cause arbitrary code execution2023-05-08
CVE-2023-31039 (CRITICAL CVSS 9.8) | Security vulnerability in Apache bR | cvebase.io