CVE-2020-13949
Uncontrolled Resource Consumption in Apache Thrift
Description
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
Base CVSS
7.5
EPSS Score
1.54%
Introduced Version
0.9.3
Fix Available
0.14.0
Available Patches
Package
CVEs Fixed
Lines of Code Changed