Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hr4p-8hm2-w85x

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.

Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.

EPSS

Процентиль: 70%
0.00642
Низкий

Связанные уязвимости

CVSS3: 7.5
nvd
почти 6 лет назад

Java Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.12.09.00.

EPSS

Процентиль: 70%
0.00642
Низкий