REDHAT-BUG-2466671: Path Traversal
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'), Uncontrolled Resource Consumption vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Thriftto a version that resolves this vulnerability.Fixed in 0.23.0
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2466671?
The severity of REDHAT-BUG-2466671 is classified as high with a score of 7.
What vulnerabilities are associated with REDHAT-BUG-2466671?
REDHAT-BUG-2466671 includes vulnerabilities such as Path Traversal, HTTP Request/Response Splitting, and Uncontrolled Resource Consumption.
How do I fix REDHAT-BUG-2466671?
To fix REDHAT-BUG-2466671, you should update to the latest patched version of Apache Thrift.
What impact does REDHAT-BUG-2466671 have on systems?
REDHAT-BUG-2466671 can lead to unauthorized access, data leakage, and potential denial of service.
Is REDHAT-BUG-2466671 specific to a certain version of Apache Thrift?
Yes, REDHAT-BUG-2466671 affects specific versions of Apache Thrift, and users should consult release notes for details.