In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade thrift | Aug 22, 2024 | Feb 12, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 12, 2021 |
| Debian | — | Upgrade thrift | Jul 30, 2024 | Feb 12, 2021 |
| Gentoo Linux | — | Upgrade dev-python/thrift. | Jul 16, 2021 | Feb 12, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade isula-sec | Jun 2, 2021 | Feb 12, 2021 |
| Red Hat Jboss Eap | — | — | Sep 19, 2024 | Feb 11, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub