Apache Thrift vulnerabilities
2 known vulnerabilities affecting apache/apache_thrift.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-0210HIGHCVSS 7.5v0.9.3 to 0.12.02019-10-29
CVE-2019-0210 [HIGH] CWE-125 CVE-2019-0210: In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProto
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
cvelistv5nvd
CVE-2019-0205HIGHCVSS 7.5vall versions up to and including 0.12.02019-10-29
CVE-2019-0205 [HIGH] CWE-835 CVE-2019-0205: In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
cvelistv5nvd