Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: apache
Published: 2019-01-07T18:00:00
Updated: 2021-09-24T16:06:13
Reserved: 2017-12-07T00:00:00
Link: CVE-2018-1320
JSON object: View
NVD Information
Status : Modified
Published: 2019-01-07T17:29:00.360
Modified: 2023-11-07T02:55:57.850
Link: CVE-2018-1320
JSON object: View
Redhat Information
No data.
CWE