Описание
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
A flaw was found in thrift. Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Distributed Tracing Jaeger 1 | jaeger | Not affected | ||
| OpenShift Service Mesh 1 | jaeger | Not affected | ||
| Red Hat Fuse 7 | camel-thrift | Not affected | ||
| Red Hat Fuse 7 | libthrift | Not affected | ||
| Red Hat JBoss Data Grid 7 | libthrift | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | libthrift | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | jaeger-thrift | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 7 | libthrift | Not affected | ||
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | libthrift | Not affected | ||
| Red Hat JBoss Fuse 6 | libthrift | Out of support scope |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
Golang Facebook Thrift servers vulnerable to denial of service
EPSS
7.5 High
CVSS3