Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-1320

Опубликовано: 05 мар. 2018
Источник: redhat
CVSS3: 6.5

Описание

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

Отчет

OpenDaylight: OpenDaylight includes libthrift, however does not use the vulnerable functionality. OpenDaylight should be considered not affected by this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat JBoss Data Virtualization 6libthriftOut of support scope
Red Hat JBoss Enterprise Application Platform 7libthriftNot affected
Red Hat JBoss Enterprise Application Platform Continuous DeliverylibthriftNot affected
Red Hat JBoss Fuse Service Works 6thriftOut of support scope
Red Hat JBoss Operations Network 3libthriftNot affected
Red Hat OpenShift Application RuntimeslibthriftOut of support scope
Red Hat OpenShift Container Platform 4thriftNot affected
Red Hat OpenShift Enterprise 3thriftNot affected
Red Hat OpenStack Platform 10 (Newton)libthriftWill not fix
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-287
https://bugzilla.redhat.com/show_bug.cgi?id=1667204thrift: SASL negotiation isComplete validation bypass in the org.apache.thrift.transport.TSaslTransport class

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
больше 7 лет назад

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

CVSS3: 7.5
nvd
больше 7 лет назад

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

CVSS3: 7.5
debian
больше 7 лет назад

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can by ...

CVSS3: 7.5
github
больше 7 лет назад

Improper Input Validation in Apache Thrift

CVSS3: 7.5
fstec
больше 7 лет назад

Уязвимость класса org.apache.thrift.transport.TSaslTransport языка описания интерфейсов Apache Thrift, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

6.5 Medium

CVSS3