Critical Flaws in Apache Thrift Threaten Multi-Language
ID: ba2b7978-ab09-5748-9594-9f51220f9499
STIX ID: report--ba2b7978-ab09-5748-9594-9f51220f9499
Feed Name: securityonline.info
Apache Thrift released an urgent 0.23.0 update addressing three security flaws across its Rust, Java, and Node.js implementations: a memory-allocation exhaustion leading to DoS, a Java TLS hostname verification failure that can enable Man-in-the-Middle interception, and a multi-vulnerability issue in Node.js (path traversal, HTTP splitting, origin validation errors, and resource exhaustion). Organizations using Thrift should upgrade immediately and audit multi-language service dependencies to mitigate cascading risks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
