HIGH · 7.5

CVE-2019-0205

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in vers...

Vulnerability Description

In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in version 0.11.0, depending on the installed version it affects only certain language bindings.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
ApacheThrift<= 0.12.0
RedhatJboss Enterprise Application Platform7.2.0
RedhatEnterprise Linux Server6.0
OracleCommunications Cloud Native Core Network Slice Selection Function1.2.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-0205?

CVE-2019-0205 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache Thrift all versions up to and including 0.12.0, a server or client may run into an endless loop when feed with specific input data. Because the issue had already been partially fixed in vers...

How severe is CVE-2019-0205?

CVE-2019-0205 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-0205?

Check the references section above for vendor advisories and patch information. Affected products include: Apache Thrift, Redhat Jboss Enterprise Application Platform, Redhat Enterprise Linux Server, Oracle Communications Cloud Native Core Network Slice Selection Function.