Описание
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings.
This issue affects Apache Thrift: from 0.19.0 before 0.24.0.
Users are recommended to upgrade to version 0.24.0, which fixes the issue.
A flaw was found in Apache Thrift Java bindings. This vulnerability, categorized as an Allocation of Resources Without Limits or Throttling, allows a remote attacker to cause a denial of service by exhausting system resources. The flaw occurs when the application fails to properly limit or throttle resource allocation, leading to potential system instability or unresponsiveness.
Отчет
This vulnerability is rated as Important. It affects Apache Thrift Java bindings, which could lead to a denial of service due to uncontrolled resource allocation. This impacts Red Hat OpenShift Container Platform and Community Projects where vulnerable versions of Apache Thrift are utilized, potentially allowing an attacker to exhaust system resources.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Not affected | ||
| Cryostat 4 | cryostat/cryostat-storage-rhel9 | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | libthrift | Affected | ||
| Red Hat Ceph Storage 5 | rhceph/rhceph-5-dashboard-rhel8 | Affected | ||
| Red Hat Ceph Storage 6 | rhceph/rhceph-6-dashboard-rhel9 | Affected | ||
| Red Hat Ceph Storage 7 | rhceph/grafana-rhel9 | Affected | ||
| Red Hat Ceph Storage 8 | rhceph/grafana-rhel9 | Affected | ||
| Red Hat Ceph Storage 9 | rhceph/alloy-rhel10 | Affected | ||
| Red Hat Connectivity Link 1 | rhcl-1/authorino-rhel9 | Affected | ||
| Red Hat Data Grid 8 | libthrift | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in ...
Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Java bindings. This issue affects Apache Thrift: from 0.19.0 before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
EPSS
7.5 High
CVSS3