CVE-2018-1320: Apache Thrift

High severity, CVSS 7.5. EPSS: 8.2% chance of exploitation in the next 30 days.

Apache Thrift Java client library versions 0.5.0 through 0.11.0 can bypass SASL negotiation isComplete validation in the org.apache.thrift.transport.TSaslTransport class. An assert used to determine if the SASL handshake had successfully completed could be disabled in production settings making the validation incomplete.

Affected products

  • Apache Thrift: from 0.5.0, up to and including 0.11.0
  • Debian Debian Linux: version 8.0 only
  • F5 Traffix Signaling Delivery Controller: from 5.0.0, up to and including 5.1.0
  • Oracle Global Lifecycle Management Opatch: before 11.2.0.3.23 (fixed in 11.2.0.3.23); from 12.2.0.1.0, before 12.2.0.1.19 (fixed in 12.2.0.1.19); from 13.9.4.0.0, before 13.9.4.2.1 (fixed in 13.9.4.2.1)
  • Oracle Nosql Database: before 19.3.12 (fixed in 19.3.12)

Published 2019-01-07. Last modified 2026-06-17.