Back

HIGH

thrift: SASL negotiation isComplete validation bypass in the org.apache.thrift.transport.TSaslTransport class

Published Jan 7, 2019

Description

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

Affected products

Remediation

Red Hat statement

OpenDaylight: OpenDaylight includes libthrift, however does not use the vulnerable functionality. OpenDaylight should be considered not affected by this flaw.

Metrics

References (53)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 7, 2019
Updated Aug 5, 2024
Reserved Dec 7, 2017
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Mar 5, 2018
GHSA-WJXJ-F8RG-99WX