Описание
A flaw was found in Apache Thrift Node.js bindings. This vulnerability, stemming from inefficient algorithmic complexity and the allocation of resources without proper limits or throttling, allows a remote attacker to cause a Denial of Service (DoS). By exploiting this, an attacker can consume excessive resources, making the service unavailable to legitimate users.
Отчет
This is an Important denial of service vulnerability in Apache Thrift Node.js bindings, which could allow a remote attacker to exhaust system resources due to inefficient algorithmic complexity. This flaw primarily impacts Red Hat OpenShift Container Platform components that utilize the vulnerable Thrift Node.js bindings, potentially leading to service unavailability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-podvm-payload-rhel9 | Affected | ||
| Red Hat Enterprise Linux AI (RHEL AI) 3 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 4 | conmon-rs | Affected | ||
| Red Hat OpenShift Container Platform 4 | kata-containers | Affected | ||
| Red Hat OpenShift Update Service | openshift-update-service/openshift-update-service-rhel8 | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...
Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings. This issue affects Apache Thrift: before 0.24.0. Users are recommended to upgrade to version 0.24.0, which fixes the issue.
EPSS
7.5 High
CVSS3