The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: apache

Published: 2017-01-13T00:00:00

Updated: 2020-06-04T16:06:16

Reserved: 2016-06-10T00:00:00


Link: CVE-2016-5397

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2018-02-12T17:29:00.213

Modified: 2023-11-07T02:33:38.787


Link: CVE-2016-5397

JSON object: View

cve-icon Redhat Information

No data.

CWE