QID 980533
QID 980533: Java (maven) Security Update for org.apache.thrift:libthrift (GHSA-g2fg-mr77-6vrm)
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-g2fg-mr77-6vrm for updates pertaining to this vulnerability.
Vendor References
- GHSA-g2fg-mr77-6vrm -
github.com/advisories/GHSA-g2fg-mr77-6vrm
CVEs related to QID 980533
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-g2fg-mr77-6vrm | org.apache.thrift:libthrift |
|