High severity7.5NVD Advisory· Published Oct 29, 2019· Updated Jun 17, 2026
CVE-2019-0210
CVE-2019-0210
Description
In Apache Thrift 0.9.3 to 0.12.0, a server implemented in Go using TJSONProtocol or TSimpleJSONProtocol may panic when feed with invalid input data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/apache/thriftGo | >= 0.9.3, < 0.13.0 | 0.13.0 |
Affected products
12- cpe:2.3:a:oracle:communications_cloud_native_core_network_slice_selection_function:1.2.1:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:jboss_enterprise_application_platform:7.2.0:*:*:*:*:*:*:*
- osv-coords8 versionspkg:apk/chainguard/cadencepkg:apk/chainguard/cadence-cassandra-toolpkg:apk/chainguard/cadence-fipspkg:apk/chainguard/cadence-fips-cassandra-toolpkg:apk/chainguard/cadence-fips-serverpkg:apk/chainguard/cadence-fips-sql-toolpkg:apk/chainguard/cadence-sql-toolpkg:golang/github.com/apache/thrift
< 1.4.1-r0+ 7 more
- (no CPE)range: < 1.4.1-r0
- (no CPE)range: < 0
- (no CPE)range: < 1.4.1-r0
- (no CPE)range: < 0
- (no CPE)range: < 1.4.1-r0
- (no CPE)range: < 0
- (no CPE)range: < 0
- (no CPE)range: >= 0.9.3, < 0.13.0
- Apache/Apache Thriftv5Range: 0.9.3 to 0.12.0
Patches
Vulnerability mechanics
References
21- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party Advisory
- mail-archives.apache.org/mod_mbox/thrift-dev/201910.mbox/%3C277A46CA87494176B1BBCF5D72624A2A%40HAGGIS%3EnvdMailing ListVendor AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0804nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0805nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0806nvdThird Party AdvisoryWEB
- access.redhat.com/errata/RHSA-2020:0811nvdThird Party AdvisoryWEB
- github.com/advisories/GHSA-jq7p-26h5-w78rghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-0210ghsaADVISORY
- security.gentoo.org/glsa/202107-32nvdThird Party AdvisoryWEB
- github.com/apache/thrift/blob/master/CHANGES.mdghsaWEB
- github.com/apache/thrift/commit/264a3f318ed3e9e51573f67f963c8509786bcec2ghsaWEB
- lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851473194a247392f@%3Ccommits.pulsar.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7ccdae6dd47a877a9@%3Ccommits.pulsar.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024df0d848d6915ff@%3Ccommits.pulsar.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c4256c2e5e5e142@%3Ccommits.pulsar.apache.org%3EghsaWEB
- pkg.go.dev/vuln/GO-2021-0101ghsaWEB
- www.oracle.com/security-alerts/cpujul2021.htmlghsaWEB
- lists.apache.org/thread.html/r2832722c31d78bef7526e2c701ba4b046736e4c851473194a247392f%40%3Ccommits.pulsar.apache.org%3Envd
- lists.apache.org/thread.html/r36581cc7047f007dd6aadbdd34e18545ec2c1eb7ccdae6dd47a877a9%40%3Ccommits.pulsar.apache.org%3Envd
- lists.apache.org/thread.html/r55609613abab203a1f2c1f3de050b63ae8f5c4a024df0d848d6915ff%40%3Ccommits.pulsar.apache.org%3Envd
- lists.apache.org/thread.html/rab740e5c70424ef79fd095a4b076e752109aeee41c4256c2e5e5e142%40%3Ccommits.pulsar.apache.org%3Envd
News mentions
0No linked articles in our index yet.