Back to search
CVE-2020-13949
Published: Feb 12, 2021
Modified: Aug 4, 2024
PUBLISHED
Description
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
| Vendor | Product | Versions |
|---|---|---|
n/a | Apache Thrift | affected Apache Thrift 0.9.3 to 0.13.0 |
References
[hbase-issues] 20210215 [jira] [Work started] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210215 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210216 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[thrift-user] 20210217 Apache Thrift 0.14.0 Release not on Maven central
mailing-list
x_refsource_MLIST
[thrift-user] 20210224 Re: [SECURITY] CVE-2020-13949 Announcement
mailing-list
x_refsource_MLIST
[hbase-issues] 20210302 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210302 [jira] [Updated] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210308 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210310 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[thrift-user] 20210312 Thrift 0.13 micro for CVE-2020-13949?
mailing-list
x_refsource_MLIST
[thrift-user] 20210312 RE: Thrift 0.13 micro for CVE-2020-13949?
mailing-list
x_refsource_MLIST
[hbase-issues] 20210316 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210317 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210318 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210319 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210319 [jira] [Comment Edited] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210320 RE: [jira] [Work started] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210324 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[druid-commits] 20210324 [GitHub] [druid] jihoonson opened a new issue #11028: Bump Thrift library version
mailing-list
x_refsource_MLIST
[druid-commits] 20210324 [GitHub] [druid] jihoonson opened a new pull request #11030: Suppress cves
mailing-list
x_refsource_MLIST
[hbase-issues] 20210325 [jira] [Updated] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210325 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210326 [jira] [Updated] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210326 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hbase-issues] 20210415 [jira] [Commented] (HBASE-25568) Upgrade Thrift jar to fix CVE-2020-13949
mailing-list
x_refsource_MLIST
[hive-dev] 20210510 [jira] [Created] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.0 due
mailing-list
x_refsource_MLIST
[hive-issues] 20210510 [jira] [Updated] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.0
mailing-list
x_refsource_MLIST
[hive-issues] 20210510 [jira] [Assigned] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.0 due
mailing-list
x_refsource_MLIST
[hive-issues] 20210517 [jira] [Updated] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
mailing-list
x_refsource_MLIST
[hive-issues] 20210530 [jira] [Work started] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
mailing-list
x_refsource_MLIST
[hive-issues] 20210530 [jira] [Updated] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
mailing-list
x_refsource_MLIST
[hive-issues] 20210609 [jira] [Work logged] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
mailing-list
x_refsource_MLIST
[hive-issues] 20210609 [jira] [Resolved] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
mailing-list
x_refsource_MLIST
[hive-issues] 20210609 [jira] [Updated] (HIVE-25098) [CVE-2020-13949] Upgrade thrift from 0.13.0 to 0.14.1
mailing-list
x_refsource_MLIST
GLSA-202107-32
vendor-advisory
x_refsource_GENTOO
https://www.oracle.com//security-alerts/cpujul2021.html
x_refsource_MISC
[thrift-user] 20210927 Analysis and guidelines concerning CVE-2020-13949
mailing-list
x_refsource_MLIST
[thrift-user] 20211004 Re: Analysis and guidelines concerning CVE-2020-13949
mailing-list
x_refsource_MLIST
https://www.oracle.com/security-alerts/cpujan2022.html
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now