Overview
About vulnerability
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.
Details
- Affected product:
- Grafana , Loki , MinIO , apache/arrow-go , apache/arrow/go , apache/thrift , bufbuild/protoc-gen-validate , centrifugal/centrifuge , cncf/xds/go , coredns/coredns , etcd-io/etcd/client , fraugster/parquet-go , go-kit/kit , googleapis/gax-go , googleapis/google-api-go-client , googleapis/google-cloud-go-testing , googleapis/google-cloud-go/bigquery , grafana/grafana-azure-sdk-go , grafana/grafana-plugin-sdk-go , grafana/tempo , grpc-ecosystem/go-grpc-middleware , grpc-ecosystem/go-grpc-prometheus , grpc/grpc-go , hashicorp/consul , influxdata/telegraf , jaegertracing/jaeger , kubernetes/component-base , lyft/protoc-gen-star , open-telemetry/opentelemetry-collector , open-telemetry/opentelemetry-go/exporters/otlp/otlptrace/otlptracegrpc , prometheus/client_golang , prometheus/common , scottlepp/go-duck , spf13/afero
- Affected packages:
- github.com/apache/thrift @ 0.21.0 (+69 more)
Integer Overflow or Wraparound vulnerability in Apache Thrift TFramedTransport Go language implementation
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issue.