Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Uncontrolled Resource Consumption in Apache Thrift

GHSA-g2fg-mr77-6vrm · BIT-thrift-2020-13949 · CVE-2020-13949

Published · Modified

Description

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

References

Ready to move

Start Securing

Free, no credit card | First findings in minutes