apache thrift CVE-2020-13949 in Apache and Oracle Products
Published on February 12, 2021

product logo product logo product logo
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.

Vendor Advisory NVD


Products Associated with CVE-2020-13949

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2020-13949 are published in these products:

 
 
 
 

Exploit Probability

EPSS
0.74%
Percentile
72.49%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.