Affected resources
gRPC Erlang versions prior to 1.0.0, starting from version 0.4.0 inclusive.
Peter Ullrich has discovered a vulnerability in the gRPC protocol implementation for Elixir that can cause the entire BEAM node to collapse by exhausting the atom table and, when a decoded term flows to a call site that invokes it, achieve remote code execution on the server.
Fix: It is recommended to upgrade to version 1.0.0.
Targeted at:
-
People working with Elixir and Erlang/OTP.
-
Affected framework or library: the gRPC Erlang package, which is the gRPC protocol implementation for Elixir.
It has a Critical severity rating, so an urgent update is recommended.
Regards developers,
Sergio Turpín