HIGH7.5
GHSA-w3r9-r9w7-8h48
Golang Facebook Thrift servers vulnerable to denial of service
Quick fix
GHSA-w3r9-r9w7-8h48 — github.com/facebook/fbthrift: upgrade to the fixed version with the command below.
go get github.com/facebook/fbthrift@v0.31.1-0.20200311080807-483ed864d69fDetails
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
### Specific Go Packages Affected github.com/facebook/fbthrift/thrift/lib/go/thrift
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/facebook/fbthrift
Introduced in:
0Fixed in: 0.31.1-0.20200311080807-483ed864d69fFix
go get github.com/facebook/fbthrift@v0.31.1-0.20200311080807-483ed864d69f