Skip to main content

Vendor/product archive

apache / thrift CVEs

Beta · best-effort

32 CVEs tagged to apache / thrift2 Critical, 21 High, 9 Medium, 0 Low, 0 Unrated.

CVE-2018-11798

Published Jan 7, 2019

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to acc…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2016-5397

Published Feb 12, 2018

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and o…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2015-3254

Published Jun 16, 2017

The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 26-32 of 32 CVEsPage 2 of 2