VDB
Sign up
HIGH7.5

GHSA-wjxj-f8rg-99wx

Improper Input Validation in Apache Thrift

Quick fix

GHSA-wjxj-f8rg-99wx — org.apache.thrift:libthrift: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.9.3-1</version> for org.apache.thrift:libthrift

Details

Apache Thrift Java client library versions 0.5.0 prior to 0.9.3-1 and 0.10.0 prior to 0.12.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.thrift:libthrift
Introduced in: 0.5.0Fixed in: 0.9.3-1
Fix# pom.xml: bump <version>0.9.3-1</version> for org.apache.thrift:libthrift
Maven/org.apache.thrift:libthrift
Introduced in: 0.10.0Fixed in: 0.12.0
Fix# pom.xml: bump <version>0.12.0</version> for org.apache.thrift:libthrift

References