Описание
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Ссылки
- Release Notes
- Vendor Advisory
- Mailing ListThird Party Advisory
Уязвимые конфигурации
EPSS
7.5 High
CVSS3
Дефекты
Связанные уязвимости
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A flaw was found in Apache Thrift Ruby bindings. This vulnerability, categorized as improper handling of highly compressed data, allows a remote attacker to cause a denial of service (DoS) through a data amplification attack. By sending specially crafted highly compressed data, an attacker can exhaust system resources, making the service unavailable to legitimate users.
Improper Handling of Highly Compressed Data (Data Amplification) vulne ...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
EPSS
7.5 High
CVSS3