Known Vulnerabilities for Thrift by Apache
Listed below are 7 of the newest known vulnerabilities associated with "Thrift" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2020-13949 | In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory alloca... | 7.5 - HIGH | 2021-02-12 | 2023-11-07 |
| CVE-2019-0210 | In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed w... | 7.5 - HIGH | 2019-10-29 | 2023-11-07 |
| CVE-2019-0205 | In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with spec... | 7.5 - HIGH | 2019-10-29 | 2023-11-07 |
| CVE-2018-11798 | The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulne... | 6.5 - MEDIUM | 2019-01-07 | 2023-11-07 |
| CVE-2018-1320 | Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.... | 7.5 - HIGH | 2019-01-07 | 2023-11-07 |
| CVE-2016-5397 | The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an extern... | 8.8 - HIGH | 2018-02-12 | 2023-11-07 |
| CVE-2015-3254 | The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infin... | 6.5 - MEDIUM | 2017-06-16 | 2023-02-13 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Thrift | 0.9.3.1 | All | All | All |
| Application | Apache | Thrift | 0.9.3 | All | All | All |
| Application | Apache | Thrift | 0.9.3 | All | All | All |
| Application | Apache | Thrift | 0.9.2 | All | All | All |
| Application | Apache | Thrift | 0.9.2 | All | All | All |
| Application | Apache | Thrift | 0.9.1 | All | All | All |
| Application | Apache | Thrift | 0.9.1 | All | All | All |
| Application | Apache | Thrift | 0.9.0 | All | All | All |
| Application | Apache | Thrift | 0.9.0 | All | All | All |
| Application | Apache | Thrift | 0.8.0 | All | All | All |
| Application | Apache | Thrift | 0.8.0 | All | All | All |
| Application | Apache | Thrift | 0.7.0 | All | All | All |
| Application | Apache | Thrift | 0.7.0 | All | All | All |
| Application | Apache | Thrift | 0.6.1 | All | All | All |
| Application | Apache | Thrift | 0.6.1 | All | All | All |
| Application | Apache | Thrift | 0.6.0 | All | All | All |
| Application | Apache | Thrift | 0.6.0 | All | All | All |
| Application | Apache | Thrift | 0.5.0 | All | All | All |
| Application | Apache | Thrift | 0.5.0 | All | All | All |
| Application | Apache | Thrift | 0.4.0 | All | All | All |