CVE Database
/

CVE-2018-1320

Back to search

CVE-2018-1320

Published: Jan 7, 2019

Modified: Aug 5, 2024

PUBLISHED

Description

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

VendorProductVersions

Apache Software Foundation

Apache Thrift

affected
Apache Thrift 0.5.0 to 0.11.0

References

106551
vdb-entry
x_refsource_BID
RHSA-2019:2413
vendor-advisory
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now