CVE-2019-0210
published 2019-10-29CVE-2019-0210: In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
PriorityP344high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
6.85%
93.3th percentile
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | apache_thrift | — | — |
| apache | thrift | 0.9.3 – 0.12.0 | — |
| debian | thrift | < thrift 0.13.0-2 (bookworm) | thrift 0.13.0-2 (bookworm) |
| thrift | >= 0 < 0.13.0-2 | 0.13.0-2 | |
| thrift | >= 0 < 0.13.0-2 | 0.13.0-2 | |
| thrift | >= 0 < 0.13.0-2 | 0.13.0-2 | |
| thrift | >= 0 < 0.13.0-2 | 0.13.0-2 | |
| github.com | apache_thrift | >= 0.0.0-20151001171628-53dd39833a08 < 0.13.0 | 0.13.0 |
| github.com | apache_thrift | >= 0.9.3 < 0.13.0 | 0.13.0 |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| redhat | jboss_enterprise_application_platform | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Panic due to out-of-bounds read in github.com/apache/thrift
osv·2021-07-28
CVE-2019-0210 Panic due to out-of-bounds read in github.com/apache/thrift
Panic due to out-of-bounds read in github.com/apache/thrift
Due to an improper bounds check, parsing maliciously crafted messages can cause panics. If this package is used to parse untrusted input, this may be used as a vector for a denial of service attack.
GHSA
Out-of-bounds read in Apache Thrift
ghsa·2021-05-18
CVE-2019-0210 [HIGH] CWE-125 Out-of-bounds read in Apache Thrift
Out-of-bounds read in Apache Thrift
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
OSV
Out-of-bounds read in Apache Thrift
osv·2021-05-18
CVE-2019-0210 [HIGH] Out-of-bounds read in Apache Thrift
Out-of-bounds read in Apache Thrift
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
OSV
CVE-2019-0210: In Apache Thrift 0
osv·2019-10-29·CVSS 7.5
CVE-2019-0210 [HIGH] CVE-2019-0210: In Apache Thrift 0
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Red Hat
thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol
vendor_redhat·2019-10-17·CVSS 7.5
CVE-2019-0210 [HIGH] CWE-125 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol
thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Statement: Red Hat OpenStack Platform ships OpenDaylight, which contains a vulnerable version of libthrift. However, OpenDaylight is not affected as this is a Golang specific problem, lowering the impact of the vulnerability for OpenDaylight. As such, Red Hat will not be providing a fix for OpenDaylight at this time.
The version of thrift delivered in OpenShift Container Platform is not affected by this vulnerability as it does not contain the affected code.
Package: jaeger (OpenShift Service Mesh 1) - Affected
Package: camel-thrift (Red Hat Fuse 7) - Will not fix
Debian
CVE-2019-0210: thrift - In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol...
vendor_debian·2019·CVSS 7.5
CVE-2019-0210 [HIGH] CVE-2019-0210: thrift - In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol...
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
Scope: local
bookworm: resolved (fixed in 0.13.0-2)
bullseye: resolved (fixed in 0.13.0-2)
forky: resolved (fixed in 0.13.0-2)
sid: resolved (fixed in 0.13.0-2)
trixie: resolved (fixed in 0.13.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol
bugzilla·2019-10-23·CVSS 7.5
CVE-2019-0210 [HIGH] CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol
CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol
A flaw was found in Apache Thrift versions 0.9.3 to 0.12.0. A server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
References:
https://seclists.org/oss-sec/2019/q4/29
Discussion:
Created thrift tracking bugs for this issue:
Affects: epel-7 [bug 1764609]
Affects: fedora-all [bug 1764608]
---
RHOSP: thrift is shipped in ODL which is java based, not golang which is required for this flaw.
---
libthrift version shipped with RHSSO 7.3.4 is :
rhsso-7.3.4/modules/system/layers/base/org/apache/thrift/main/libthrift-0.11.0.redhat-00006.jar which seems to be affected.
Also I am unable to locate the affected class (TJSONProtocol or TSimpleJSO
Bugzilla
CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol [epel-7]
bugzilla·2019-10-23·CVSS 7.5
CVE-2019-0210 [HIGH] CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol [epel-7]
CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol [epel-7]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-7.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
Discussion:
Use the following templ
Bugzilla
CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol [fedora-all]
bugzilla·2019-10-23·CVSS 7.5
CVE-2019-0210 [HIGH] CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol [fedora-all]
CVE-2019-0210 thrift: Out-of-bounds read related to TJSONProtocol or TSimpleJSONProtocol [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects mul
http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494176B1BBCF5D72624A2A%40HAGGIS%3Ehttps://access.redhat.com/errata/RHSA-2020:0804https://access.redhat.com/errata/RHSA-2020:0805https://access.redhat.com/errata/RHSA-2020:0806https://access.redhat.com/errata/RHSA-2020:0811https://lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851473194a247392f%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7ccdae6dd47a877a9%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024df0d848d6915ff%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c4256c2e5e5e142%40%3Ccommits.pulsar.apache.org%3Ehttps://security.gentoo.org/glsa/202107-32https://www.oracle.com//security-alerts/cpujul2021.htmlhttp://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494176B1BBCF5D72624A2A%40HAGGIS%3Ehttps://access.redhat.com/errata/RHSA-2020:0804https://access.redhat.com/errata/RHSA-2020:0805https://access.redhat.com/errata/RHSA-2020:0806https://access.redhat.com/errata/RHSA-2020:0811https://lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851473194a247392f%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7ccdae6dd47a877a9%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024df0d848d6915ff%40%3Ccommits.pulsar.apache.org%3Ehttps://lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c4256c2e5e5e142%40%3Ccommits.pulsar.apache.org%3Ehttps://security.gentoo.org/glsa/202107-32https://www.oracle.com//security-alerts/cpujul2021.html
2019-10-29
Published