Impact
The vulnerability in Apache Thrift’s Perl bindings leads to the TLS client disabling certificate verification by default. This flaw, identified as improper certificate validation, allows an attacker to intercept, alter or forge traffic between the client and server. With certificate checks turned off, the communication channel is effectively trust‑based, eroding confidentiality and data integrity.
Affected Systems
Apache Thrift servers and clients built with the Apache Software Foundation’s Thrift framework, specifically all releases older than version 0.25.0, are susceptible. Applications using the Perl bindings before the 0.25.0 release are at risk.
Risk and Exploitability
CVSS indicates a score of 6.9, reflecting a moderate severity level. The EPSS metric is not published, implying limited current exploitation activity. The vulnerability is not listed in CISA’s KEV catalog. Attackers could exploit this issue remotely by establishing a TLS connection over which they could conduct man‑in‑the‑middle attacks, a vector that is feasible where network traffic is untrusted. The flaw requires no elevated privileges and relies on the default configuration; thus any deployment of these bindings without a manual override of verification is vulnerable.
OpenCVE Enrichment