Описание
A flaw was found in Apache Thrift Ruby bindings. This vulnerability, categorized as improper handling of highly compressed data, allows a remote attacker to cause a denial of service (DoS) through a data amplification attack. By sending specially crafted highly compressed data, an attacker can exhaust system resources, making the service unavailable to legitimate users.
Отчет
This Important vulnerability in Apache Thrift Ruby bindings could allow a remote, unauthenticated attacker to trigger a denial of service. By sending specially crafted compressed data, an attacker can cause excessive resource consumption, leading to service unavailability in affected Red Hat products that utilize these bindings, such as OpenShift Container Platform components.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Affected | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 4 | conmon-rs | Not affected | ||
| Red Hat OpenShift Container Platform 4 | kata-containers | Affected | ||
| Red Hat OpenShift Update Service | openshift-update-service/openshift-update-service-rhel8 | Affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Improper Handling of Highly Compressed Data (Data Amplification) vulne ...
Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in Apache Thrift Ruby bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
7.5 High
CVSS3