VDB
Sign up
HIGH7.5

GHSA-g2fg-mr77-6vrm

Uncontrolled Resource Consumption in Apache Thrift

Quick fix

GHSA-g2fg-mr77-6vrm — org.apache.thrift:libthrift: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.14.0</version> for org.apache.thrift:libthrift

Details

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.thrift:libthrift
Introduced in: 0.9.3Fixed in: 0.14.0
Fix# pom.xml: bump <version>0.14.0</version> for org.apache.thrift:libthrift

References