Input validation error in Thrift - CVE-2020-13949

 

Input validation error in Thrift - CVE-2020-13949

Published: February 15, 2021


Vulnerability identifier: #VU50684
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-13949
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can send specially crafted messages and perform a denial of service (DoS) attack.


Affected software

Thrift
Gentoo Linux
Arch Linux
Log Analysis
IBM Security Guardium Insights
Netcool Operations Insight
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Watson Assistant for IBM Cloud Pak for Data
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift Jaeger
IBM Qradar SIEM
IBM Security Guardium
Gitlab Community Edition
GitLab Enterprise Edition
IBM Cloud Pak for Watson AIOps
Fuse

How to mitigate CVE-2020-13949

Install updates from vendor's website.

Thrift - update to 0.14.0
Log Analysis - update to 1.3.7.2 FP2
Red Hat OpenShift Jaeger - update to 1.20.4
IBM Security Guardium Insights - update to 3.0
IBM Qradar SIEM - addressed in versions 7.3.3 Fix Pack 8, 7.4.3 Fix Pack 1
Gitlab Community Edition - addressed in versions 13.7.8, 13.8.5, 13.9.2
GitLab Enterprise Edition - addressed in versions 13.7.8, 13.8.5, 13.9.2
Netcool Operations Insight - update to 1.6.6
IBM Cloud Pak for Watson AIOps - update to 3.6.2
IBM Watson Discovery for IBM Cloud Pak for Data - update to 4.6.5
IBM Watson Assistant for IBM Cloud Pak for Data - update to 5.0.1
Fuse - update to 7.10.0

External References

Related Security Bulletins