VYPR
High severity7.5NVD Advisory· Published Jan 7, 2019· Updated Jun 17, 2026

CVE-2018-1320

CVE-2018-1320

Description

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.thrift:libthriftMaven
>= 0.5.0, < 0.9.3-10.9.3-1
org.apache.thrift:libthriftMaven
>= 0.10.0, < 0.12.00.12.0

Affected products

10

Patches

Vulnerability mechanics

References

50

News mentions

0

No linked articles in our index yet.