Описание
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Отчет
Red Hat OpenStack Platform ships OpenDaylight, which contains a vulnerable version of libthrift. However, OpenDaylight is not affected as this is a Golang specific problem, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time. The version of thrift delivered in OpenShift Container Platform is not affected by this vulnerability as it does not contain the affected code.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Service Mesh 1 | jaeger | Affected | ||
| Red Hat Fuse 7 | camel-thrift | Will not fix | ||
| Red Hat JBoss Data Virtualization 6 | libthrift | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jaeger-thrift | Not affected | ||
| Red Hat JBoss Fuse 6 | libthrift | Out of support scope | ||
| Red Hat JBoss Fuse Service Works 6 | thrift | Out of support scope | ||
| Red Hat JBoss Operations Network 3 | libthrift | Out of support scope | ||
| Red Hat OpenShift Application Runtimes | jaeger-thrift | Not affected | ||
| Red Hat OpenShift Application Runtimes | libthrift | Affected | ||
| Red Hat OpenShift Container Platform 3.10 | thrift | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJS ...
Уязвимость библиотеки Apache Thrift прикладного программного обеспечения Аврора Центр, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3