Re: [grpc-io] Re: Affected versions - CVE-2023-32731

2023-08-30 Thread 'Eugene Ostroukhov' via grpc.io
Yes. Python module calls into C code. On Wed, Aug 30, 2023 at 11:48 AM Josef Cacek wrote: > Thank you for the reply, Eugene. > Is the response also valid for the Python grpcio module? > Regards, > -- Josef > > st 30. 8. 2023 v 19:15 odesílatel 'Eugene Ostroukhov' via grpc.io > napsal: > > > >

Re: [grpc-io] Re: Affected versions - CVE-2023-32731

2023-08-30 Thread Josef Cacek
Thank you for the reply, Eugene. Is the response also valid for the Python grpcio module? Regards, -- Josef st 30. 8. 2023 v 19:15 odesílatel 'Eugene Ostroukhov' via grpc.io napsal: > > This does not seem to apply to gRPC Java as that one is a separate codebase. > > 1.48 does not seem to have

[grpc-io] Re: Affected versions - CVE-2023-32731

2023-08-30 Thread 'Eugene Ostroukhov' via grpc.io
This does not seem to apply to gRPC Java as that one is a separate codebase. 1.48 does not seem to have this specific vulnerability it is no longer maintained and will not receive fixes if any new issues are discovered. We would recommend you to switch to a more current gRPC version. On