The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2022-5087 | The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0. |
![]() |
GHSA-r4m4-pmvw-m6j5 | Apache Thrift Go Library Command Injection |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-16T20:47:38.486Z
Reserved: 2016-06-10T00:00:00
Link: CVE-2016-5397

No data.

Status : Modified
Published: 2018-02-12T17:29:00.213
Modified: 2024-11-21T02:54:14.087
Link: CVE-2016-5397


No data.