CVE-2019-0205
Last modified
CVE-2019-0205 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.. EPSS estimates a 9.08% chance of exploitation in the next 30 days.
Description
In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Thrift | <= 0.12.0 |
| Redhat | Jboss Enterprise Application Platform | 7.2.0 |
| Oracle | Communications Cloud Native Core Network Slice Selection Function | 1.2.1 |
References
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0811Third Party Advisory
- https://security.gentoo.org/glsa/202107-32Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0811Third Party Advisory
- https://security.gentoo.org/glsa/202107-32Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatch, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-0205?
How severe is CVE-2019-0205?
How do I fix CVE-2019-0205?
Are you affected by CVE-2019-0205?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
