CyberRota Analysis
AI-GeneratedApache Thrift versions prior to 0.25.0 are vulnerable due to improper handling of length parameters, which can lead to uncaught exceptions and excessive memory allocation, potentially resulting in denial-of-service conditions. This high-severity vulnerability impacts multiple language bindings, including Java, Python, and Ruby, making it critical for organizations using these technologies to prioritize upgrading to version 0.25.0 to mitigate risks.
Original NVD Description
Improper handling of length parameter inconsistency, Uncaught exception, Inefficient Algorithmic Complexity, Memory allocation with excessive size value, Initialization of a resource with an insecure default vulnerability in Apache Thrift Python, Ruby, Erlang, Lua, Dart, JavaME, Perl, PHP and D language bindings. This issue affects Apache Thrift: before 0.25.0. Users are recommended to upgrade to version 0.25.0, which fixes the issue.