HIGH8.8
GHSA-r4m4-pmvw-m6j5
Apache Thrift Go Library Command Injection
Quick fix
GHSA-r4m4-pmvw-m6j5 — github.com/apache/thrift: upgrade to the fixed version with the command below.
go get github.com/apache/thrift@v0.10.0Details
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/apache/thrift
Introduced in:
0Fixed in: 0.10.0Fix
go get github.com/apache/thrift@v0.10.0References
- https://nvd.nist.gov/vuln/detail/CVE-2016-5397[ADVISORY]
- https://access.redhat.com/errata/RHSA-2018:2669[WEB]
- https://access.redhat.com/errata/RHSA-2019:3140[WEB]
- https://issues.apache.org/jira/browse/THRIFT-3893[WEB]
- https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3E[WEB]
- https://web.archive.org/web/20210124141102/http://www.securityfocus.com/bid/103025[WEB]
- http://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3E[WEB]