TIBCOSoftware / mashling

Project Mashling
86 stars 15 forks source link

CVE-2019-0210 (High) detected in github.com/apache/thrift/lib/go/thrift-0.11.0, grafanav5.0.0-beta1 #254

Open mend-for-github-com[bot] opened 4 years ago

mend-for-github-com[bot] commented 4 years ago

CVE-2019-0210 - High Severity Vulnerability

Vulnerable Libraries - github.com/apache/thrift/lib/go/thrift-0.11.0, grafanav5.0.0-beta1

github.com/apache/thrift/lib/go/thrift-0.11.0

Apache Thrift

Dependency Hierarchy: - github.com/openzipkin/zipkin-go-opentracing-v0.3.3 (Root Library) - github.com/openzipkin/zipkin-go-opentracing/thrift/gen-go/zipkincore-v0.3.3 - :x: **github.com/apache/thrift/lib/go/thrift-0.11.0** (Vulnerable Library)

Vulnerability Details

In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.

Publish Date: 2019-10-29

URL: CVE-2019-0210

CVSS 3 Score Details (7.5)

Base Score Metrics: - Exploitability Metrics: - Attack Vector: Network - Attack Complexity: Low - Privileges Required: None - User Interaction: None - Scope: Unchanged - Impact Metrics: - Confidentiality Impact: None - Integrity Impact: None - Availability Impact: High

For more information on CVSS3 Scores, click here.

Suggested Fix

Type: Upgrade version

Origin: http://mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494176B1BBCF5D72624A2A%40HAGGIS%3E

Release Date: 2019-10-29

Fix Resolution: 0.13.0