Описание
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
Отчет
Red Hat OpenStack Platform ships OpenDaylight, which contains a vulnerable version of libthrift. However, OpenDaylight does not expose libthrift in a vulnerable way, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time. The thrift package in OpenShift Container Platform is installed only in Curator images in the Logging stack. The affected code is included in this package, it's functionality is not used. This vulnerability is therefore rated Low for OpenShift Container Platform.
Затронутые пакеты
Платформа | Пакет | Состояние | Рекомендация | Релиз |
---|---|---|---|---|
OpenShift Service Mesh 1 | jaeger | Affected | ||
Red Hat JBoss Data Virtualization 6 | libthrift | Out of support scope | ||
Red Hat JBoss Enterprise Application Platform 7 | jaeger-thrift | Not affected | ||
Red Hat JBoss Fuse 6 | libthrift | Out of support scope | ||
Red Hat JBoss Fuse Service Works 6 | thrift | Out of support scope | ||
Red Hat JBoss Operations Network 3 | libthrift | Out of support scope | ||
Red Hat OpenShift Application Runtimes | jaeger-thrift | Not affected | ||
Red Hat OpenShift Application Runtimes | libthrift | Affected | ||
Red Hat OpenShift Container Platform 3.10 | thrift | Out of support scope | ||
Red Hat OpenShift Container Platform 3.11 | thrift | Will not fix |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
In Apache Thrift all versions up to and including 0.12.0, a server or ...
Loop with Unreachable Exit Condition in Apache Thrift
EPSS
5.9 Medium
CVSS3