CVE-2020-13949 (High) detected in github.com/open-telemetry/opentelemetry-go-v0.19.0 - autoclosed #56
Labels
Mend: dependency security vulnerability
Security vulnerability detected by WhiteSource
CVE-2020-13949 - High Severity Vulnerability
Vulnerable Library - github.com/open-telemetry/opentelemetry-go-v0.19.0
OpenTelemetry Go API and SDK
Dependency Hierarchy:
Found in base branch: main
Vulnerability Details
In Apache Thrift 0.9.3 to 0.13.0, malicious RPC clients could send short messages which would result in a large memory allocation, potentially leading to denial of service.
Publish Date: 2021-02-12
URL: CVE-2020-13949
CVSS 3 Score Details (7.5)
Base Score Metrics:
Suggested Fix
Type: Upgrade version
Origin: https://lists.apache.org/thread.html/r43dc2b2e928e9d845b07ac075634cb759d91bb852421dc282f87a74a%40%3Cdev.thrift.apache.org%3E
Release Date: 2021-02-12
Fix Resolution: v0.14.0
Step up your Open Source Security Game with Mend here
The text was updated successfully, but these errors were encountered: