Facebook's branch of Apache Thrift, including a new C++ server.
github.com/facebook/[email protected] has vulnerabilities — update to latest
Update to >= 0.31.1-0.20190225164308-c461c1bd1a3e to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| high | CVE-2019-11939 | Golang Facebook Thrift servers vulnerable to denial of service | 0.31.1-0.20200311080807-483ed864d69f |
| high | CVE-2019-3564 | Improper Input Validation and Excessive Iteration in Go Facebook Thrift | 0.31.1-0.20190225164308-c461c1bd1a3e |
| unknown | CVE-2019-11939 | Denial of service via malicious message size declaration in github.com/facebook/fbthrift | 0.31.1-0.20200311080807-483ed864d69f |
| unknown | CVE-2019-3564 | Denial of service via ignored unknown fields in github.com/facebook/fbthrift | 0.31.1-0.20190225164308-c461c1bd1a3e |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/github.com/facebook/fbthriftLast updated · 2015-08-24T20:47:32Z