Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:8122
HistoryJan 08, 2019 - 2:29 a.m.

Authentication Bypass

2019-01-0802:29:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14

EPSS

0.002

Percentile

59.2%

libthrift is vulnerable to authentication bypass. An assert which is used to determine the successful completion of an SASL handshake can be disabled in production settings, making the validation incomplete. An attacker is able to exploit this vulnerability to bypass the isComplete validation in org.apache.thrift.transport.TSaslTransport during the SASL negotiation.

References