Описание
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings.
This issue affects Apache Thrift: before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A flaw was found in Apache Thrift Python bindings. This vulnerability involves the improper handling of highly compressed data, leading to a data amplification issue. An attacker could exploit this by providing specially crafted compressed input, which may cause the application to consume excessive resources. This could potentially result in a denial of service (DoS) for affected systems.
Отчет
This Important vulnerability in Apache Thrift Python bindings can lead to a Denial of Service due to improper handling of highly compressed data, causing data amplification. Red Hat products such as OpenShift Container Platform, Red Hat OpenShift Update Service, and Confidential Compute Attestation are affected when processing untrusted input via these bindings, potentially exhausting system resources.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Not affected | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 4 | conmon-rs | Not affected | ||
| Red Hat OpenShift Container Platform 4 | kata-containers | Not affected | ||
| Red Hat OpenShift Update Service | openshift-update-service/openshift-update-service-rhel8 | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Apache Thrift: Unbounded Zlib Decompression in Python THeaderTransport
Improper Handling of Highly Compressed Data (Data Amplification) vulne ...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Python bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
EPSS
7.5 High
CVSS3