Back to search
CVE-2016-5397
Published: Feb 12, 2018
Modified: Sep 16, 2024
PUBLISHED
Description
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
| Vendor | Product | Versions |
|---|---|---|
Apache Software Foundation | Apache Thrift | affected versions prior to 0.10.0 |
References
103025
vdb-entry
x_refsource_BID
RHSA-2018:2669
vendor-advisory
x_refsource_REDHAT
https://issues.apache.org/jira/browse/THRIFT-3893
x_refsource_CONFIRM
[user] 20170113 [NOTICE]: Apache Thrift Security Vulnerability CVE-2016-5397
mailing-list
x_refsource_MLIST
RHSA-2019:3140
vendor-advisory
x_refsource_REDHAT
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now