CVE-2020-13949

Severity
7.5HIGH
EPSS
0.7%
top 27.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 12
Latest updateJan 15

Description

In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

Mavenorg.apache.thrift:libthrift0.9.30.14.0
NVDapache/thrift0.9.30.13.0
CVEListV5apache_thriftApache Thrift 0.9.3 to 0.13.0
NVDapache/hive< 4.0.0
Debianthrift< 0.16.0-3+2

Patches

🔴Vulnerability Details

4
OSV
Uncontrolled Resource Consumption in Apache Thrift2021-03-12
GHSA
Uncontrolled Resource Consumption in Apache Thrift2021-03-12
CVEList
CVE-2020-13949: In Apache Thrift 02021-02-12
OSV
CVE-2020-13949: In Apache Thrift 02021-02-12

📋Vendor Advisories

3
Oracle
Oracle Oracle Communications Risk Matrix: Policy (Apache Thrift) — CVE-2020-139492022-01-15
Red Hat
libthrift: potential DoS when processing untrusted payloads2021-02-11
Debian
CVE-2020-13949: thrift - In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short message...2020
CVE-2020-13949 (HIGH CVSS 7.5) | In Apache Thrift 0.9.3 to 0.13.0 | cvebase.io