VDB
Sign up
HIGH8.8

GHSA-r4m4-pmvw-m6j5

Apache Thrift Go Library Command Injection

Quick fix

GHSA-r4m4-pmvw-m6j5 — github.com/apache/thrift: upgrade to the fixed version with the command below.

go get github.com/apache/thrift@v0.10.0

Details

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/apache/thrift
Introduced in: 0Fixed in: 0.10.0
Fixgo get github.com/apache/thrift@v0.10.0

References