Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2023-45757— Apache bRPC: The builtin service rpcz page has an XSS attack vulnerability

EPSS 3.82% · P88
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2023-45757

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache bRPC: The builtin service rpcz page has an XSS attack vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Security vulnerability in Apache bRPC <=1.6.0 on all platforms allows attackers to inject XSS code to the builtin rpcz page. An attacker that can send http request to bRPC server with rpcz enabled can inject arbitrary XSS code to the builtin rpcz page. Solution (choose one of three): 1. upgrade to bRPC > 1.6.0, download link: https://dist.apache.org/repos/dist/release/brpc/1.6.1/ 2. If you are using an old version of bRPC and hard to upgrade, you can apply this patch:  https://github.com/apache/brpc/pull/2411 3. disable rpcz feature
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Apache bRPC 跨站脚本漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Apache bRPC是美国阿帕奇(Apache)基金会的用于构建可靠和高性能服务的工业级 RPC 框架。 Apache bRPC 1.6.0及之前版本存在跨站脚本漏洞,该漏洞源于允许攻击者将XSS代码注入内置rpcz页面。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Apache Software FoundationApache bRPC 0.9.0 ~ 1.6.0 -

II. Public POCs for CVE-2023-45757

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-45757

登录查看更多情报信息。

Same Patch Batch · Apache Software Foundation · 2023-10-16 · 4 CVEs total

CVE-2023-43666Apache InLong: General user Unauthorized access User Management
CVE-2023-43667Apache InLong: Log Injection in Global functions
CVE-2023-43668Apache InLong: Jdbc Connection Security Bypass in InLong

IV. Related Vulnerabilities

V. Comments for CVE-2023-45757

No comments yet


Leave a comment