thrift: Resource exhaustion via containers sizes messages
Published Mar 18, 2020
7.5
HIGHCVSS 3.1
EPSS 1.56%
Description
Golang Facebook Thrift servers would not error upon receiving messages declaring containers of sizes larger than the payload. As a result, malicious clients could send short messages which would result in a large memory allocation, potentially leading to denial of service. This issue affects Facebook Thrift prior to v2020.03.16.00.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<v2020.03.16.00
- Version v2020.03.16.00StatusunaffectedConstraints<unspecified
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Facebook Thrift | n/a |
|
No data.
Distributed Tracing Jaeger 1
jaeger
Not affected
OpenShift Service Mesh 1
jaeger
Not affected
Red Hat Fuse 7
camel-thrift
Not affected
Red Hat Fuse 7
libthrift
Not affected
Red Hat JBoss Data Grid 7
libthrift
Not affected
Red Hat JBoss Data Virtualization 6
libthrift
Out of support scope
Red Hat JBoss Enterprise Application Platform 7
jaeger-thrift
Not affected
Red Hat JBoss Enterprise Application Platform 7
libthrift
Not affected
Red Hat JBoss Enterprise Application Platform Continuous Delivery
libthrift
Not affected
Red Hat JBoss Fuse 6
libthrift
Out of support scope
Red Hat JBoss Fuse Service Works 6
thrift
Out of support scope
Red Hat JBoss Operations Network 3
libthrift
Not affected
Red Hat OpenShift Application Runtimes
jaeger-thrift
Not affected
Red Hat OpenShift Application Runtimes
libthrift
Not affected
Red Hat OpenShift Container Platform 3.11
thrift
Not affected
Red Hat OpenShift Container Platform 4
thrift
Not affected
Red Hat OpenStack Platform 10 (Newton)
opendaylight
Not affected
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Not affected
Red Hat Single Sign-On 7
jaeger-thrift
Not affected
Red Hat Single Sign-On 7
libthrift
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Distributed Tracing Jaeger 1 | jaeger | Not affected | n/a |
| OpenShift Service Mesh 1 | jaeger | Not affected | n/a |
| Red Hat Fuse 7 | camel-thrift | Not affected | n/a |
| Red Hat Fuse 7 | libthrift | Not affected | n/a |
| Red Hat JBoss Data Grid 7 | libthrift | Not affected | n/a |
| Red Hat JBoss Data Virtualization 6 | libthrift | Out of support scope | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | jaeger-thrift | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 7 | libthrift | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Continuous Delivery | libthrift | Not affected | n/a |
| Red Hat JBoss Fuse 6 | libthrift | Out of support scope | n/a |
| Red Hat JBoss Fuse Service Works 6 | thrift | Out of support scope | n/a |
| Red Hat JBoss Operations Network 3 | libthrift | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | jaeger-thrift | Not affected | n/a |
| Red Hat OpenShift Application Runtimes | libthrift | Not affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | thrift | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | thrift | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | opendaylight | Not affected | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Not affected | n/a |
| Red Hat Single Sign-On 7 | jaeger-thrift | Not affected | n/a |
| Red Hat Single Sign-On 7 | libthrift | Not affected | n/a |
github.com/facebook/fbthrift
Go
Introduced 0 Fixed 0.31.1-0.20200311080807-483ed864d69f
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/facebook/fbthrift | 0 | 0.31.1-0.20200311080807-483ed864d69f |
Remediation
No remediation recorded yet.
References (9)
- https://access.redhat.com/security/cve/CVE-2019-11939 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1816346 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5486 Advisory
- https://github.com/advisories/GHSA-w3r9-r9w7-8h48 Advisory
- https://github.com/facebook/fbthrift/commit/483ed864d69f307e9e3b9dadec048216100c0757 x_refsource_MISCPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-11939
- https://pkg.go.dev/vuln/GO-2021-0082
- https://www.cve.org/CVERecord?id=CVE-2019-11939
- https://www.facebook.com/security/advisories/cve-2019-11939 x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2019-11939 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1816346 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-5486 | Advisory | |
| https://github.com/advisories/GHSA-w3r9-r9w7-8h48 | Advisory | |
| https://github.com/facebook/fbthrift/commit/483ed864d69f307e9e3b9dadec048216100c0757 | x_refsource_MISCPatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-11939 | ||
| https://pkg.go.dev/vuln/GO-2021-0082 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-11939 | ||
| https://www.facebook.com/security/advisories/cve-2019-11939 | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.