Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2270
HistoryOct 22, 2023 - 6:11 a.m.

Advisory ROSA-SA-2023-2270

2023-10-2206:11:49
ROSA LAB
abf.rosalinux.ru
13
apache thrift 0.10.0
remote access
input validation
sasl bypass
resolved
update command
go server panic

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.1%

software: thrift 0.10.0
WASP: ROSA-CHROME

package_evr_string: thrift-0.10.0-18.src.rpm

CVE-ID: CVE-2018-1320
BDU-ID: 2019-04255
CVE-Crit: HIGH
CVE-DESC.: A vulnerability in the org.apache.thrift.transport.TSaslTransport class of the Apache Thrift interface description language is related to insufficient input validation. Exploitation of the vulnerability could allow an attacker acting remotely to gain unauthorized access to protected information by bypassing SASL negotiation
CVE-STATUS: Resolved
CVE-REV: To close, run the command: sudo dnf update thrift

CVE-ID: CVE-2018-1320
BDU-ID: 2019-03809
CVE-Crit: HIGH
CVE-DESC.: A vulnerability exists in the org.apache.thrift.transport.TSaslTransport class of the Apache Thrift interface description language due to insufficient input validation. Exploitation of the vulnerability could allow an attacker acting remotely to bypass SASL approvals
CVE-STATUS: Resolved
CVE-REV: To close, run the command: sudo dnf update thrift

CVE-ID: CVE-2019-0210
BDU-ID: None
CVE-Crit: HIGH
CVE-DESC.: In Apache Thrift 0.9.3-0.12.0, a server implemented on Go using TJSONProtocol or TSimpleJSONProtocol may panic when invalid input data is submitted.
CVE-STATUS: Fixed
CVE-REV: To close, run the command: sudo dnf update thrift

OSVersionArchitecturePackageVersionFilename
ROSAanynoarchthrift< 0.10.0UNKNOWN

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.1%