Vulnerability Description
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Thrift | >= 0.9.3, <= 0.12.0 |
| Redhat | Jboss Enterprise Application Platform | 7.2.0 |
| Redhat | Enterprise Linux Server | 6.0 |
| Oracle | Communications Cloud Native Core Network Slice Selection Function | 1.2.1 |
Related Weaknesses (CWE)
References
- http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494Mailing ListVendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0811Third Party Advisory
- https://lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851
- https://lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7cc
- https://lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024
- https://lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c
- https://security.gentoo.org/glsa/202107-32Third Party Advisory
- https://www.oracle.com//security-alerts/cpujul2021.htmlPatchThird Party Advisory
- http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494Mailing ListVendor Advisory
- https://access.redhat.com/errata/RHSA-2020:0804Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0805Third Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0806Third Party Advisory
FAQ
What is CVE-2019-0210?
CVE-2019-0210 is a vulnerability with a CVSS score of 7.5 (HIGH). In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
How severe is CVE-2019-0210?
CVE-2019-0210 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-0210?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Thrift, Redhat Jboss Enterprise Application Platform, Redhat Enterprise Linux Server, Oracle Communications Cloud Native Core Network Slice Selection Function.