VDB
Sign up
HIGH7.3

GHSA-526f-jxpj-jmg2

Apache Thrift vulnerable to Path Traversal, HTTP Request/Response Splitting, Uncontrolled Resource Consumption

Details

Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version [0.23.0](https://github.com/apache/thrift/releases/tag/v0.23.0), which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/thrift
Introduced in: 0

No fixed version published yet for thrift (npm). Pin to a known-safe version or switch to an alternative.

References