The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
https://issues.apache.org/jira/browse/THRIFT-3231
https://access.redhat.com/errata/RHSA-2017:3115
https://access.redhat.com/errata/RHSA-2017:2477