
Cloud Vulnerability DB
A community-led vulnerabilities database
A Denial of Service vulnerability was identified in grpc-ts-health-check npm package versions prior to 2.0.0. The vulnerability was discovered and reviewed on August 31, 2020, published to the GitHub Advisory Database on September 3, 2020, and last updated on January 9, 2023. This security issue has been assigned the identifier GHSA-m86m-5m44-pc93 and is classified as Low severity (GitHub Advisory, NPM Advisory).
The vulnerability exists in the grpc-ts-health-check package where an exposed API endpoint allows unauthorized manipulation of the service's health status. The issue affects all versions of the package below 2.0.0. The vulnerability has been assessed as Low severity, though no specific CVSS score or CWE classifications have been assigned (GitHub Advisory).
When exploited, this vulnerability can result in a Denial of Service condition. Specifically, attackers can manipulate the service's health status to 'failing', which causes Kubernetes to block traffic to the affected services, effectively creating a denial of service situation (GitHub Advisory).
The vulnerability can be exploited through the package's API endpoint, which allows attackers to modify the service's health status. The exploitation requires access to the API endpoint that manages the health check status (GitHub Advisory).
Users are recommended to upgrade to version 2.0.0 or later of the grpc-ts-health-check package, which contains patches for this vulnerability (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."