The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: apache
Published: 2018-02-12T17:00:00Z
Updated: 2024-09-16T20:47:38.486Z
Reserved: 2016-06-10T00:00:00
Link: CVE-2016-5397
Vulnrichment
No data.
NVD
Status : Modified
Published: 2018-02-12T17:29:00.213
Modified: 2024-11-21T02:54:14.087
Link: CVE-2016-5397
Redhat