Apache Thrift CVE-2018-11798 Access Bypass Vulnerability
BID:106501
CVE-2018-11798 |Info
Apache Thrift CVE-2018-11798 Access Bypass Vulnerability
| Bugtraq ID: | 106501 |
| Class: | Access Validation Error |
| CVE: |
CVE-2018-11798 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2019 12:00AM |
| Updated: | Jan 07 2019 12:00AM |
| Credit: | Asger Feldthaus |
| Vulnerable: |
Apache Thrift 0.11 Apache Thrift 0.10 Apache Thrift 0.9.3 Apache Thrift 0.9.2 |
| Not Vulnerable: |
Apache Thrift 0.12 |
Discussion
Apache Thrift CVE-2018-11798 Access Bypass Vulnerability
Apache Thrift is prone to an access-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Apache Thrift versions 0.9.2 through 0.11.0 are affected.
Apache Thrift is prone to an access-bypass vulnerability.
Attackers can exploit this issue to bypass security restrictions to perform unauthorized actions; this may aid in launching further attacks.
Apache Thrift versions 0.9.2 through 0.11.0 are affected.
References
Apache Thrift CVE-2018-11798 Access Bypass Vulnerability
References:
References:
- Apache Thrift Homepage (Apache)
- [SECURITY] CVE-2018-11798 Announcement (Apache Software Foundation)