VDB
Sign up
HIGH7.3

GHSA-7pwc-h2j2-rjgj

Apache Thrift has an Improper Validation of Certificate with Host Mismatch Vulnerability

Quick fix

GHSA-7pwc-h2j2-rjgj — org.apache.thrift:libthrift: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.23.0</version> for org.apache.thrift:libthrift

Details

Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.

This issue affects Apache Thrift: before 0.23.0.

Users are recommended to upgrade to version [0.23.0](https://github.com/apache/thrift/releases/tag/v0.23.0), which fixes the issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.thrift:libthrift
Introduced in: 0Fixed in: 0.23.0
Fix# pom.xml: bump <version>0.23.0</version> for org.apache.thrift:libthrift

References