The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade github.com/apache/thrift/lib/go/thrift to version 0.25.0 or higher.
github.com/apache/thrift/lib/go/thrift is a Go implementation of the Apache Thrift library.
Affected versions of this package are vulnerable to Data Amplification in THeaderTransport.parseHeaders() in lib/go/thrift/header_transport.go, which attaches a ZLIB reader to the frame whenever the header block lists that transform and places no bound on the inflated output, although ReadFrame already holds the frame itself to MaxFrameSize as it comes off the wire. An attacker can exhaust the process memory by sending a frame that stays within the wire size limit but whose ZLIB payload inflates far beyond it. This requires the application to use the Go bindings with THeaderTransport, and the transform is selected per frame by the sender in the header block rather than by the receiving application's configuration, so an application that never enables ZLIB itself still inflates frames that ask for it.