Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x4rg-4545-4w7w

Опубликовано: 15 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Improper Input Validation and Excessive Iteration in Go Facebook Thrift

Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.

Пакеты

Наименование

github.com/facebook/fbthrift

go
Затронутые версииВерсия исправления

< 0.31.1-0.20190225164308-c461c1bd1a3e

0.31.1-0.20190225164308-c461c1bd1a3e

EPSS

Процентиль: 68%
0.0056
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-755
CWE-834

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 7 лет назад

Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.

CVSS3: 7.5
nvd
почти 7 лет назад

Go Facebook Thrift servers would not error upon receiving messages with containers of fields of unknown type. As a result, malicious clients could send short messages which would take a long time for the server to parse, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2019.03.04.00.

EPSS

Процентиль: 68%
0.0056
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-755
CWE-834