Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6627-jcx5-j2g8

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.

Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.

EPSS

Процентиль: 68%
0.0056
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-755
CWE-834

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.

CVSS3: 7.5
nvd
почти 7 лет назад

Java Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.02.18.00.

EPSS

Процентиль: 68%
0.0056
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-755
CWE-834