CVE-2016-5397 Information
Description
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older Fixed in Apache Thrift 0.10.0.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Reference
http://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/3CCANyrgvc3W3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke2BOPhQ40mail.gmail.com3E http://www.securityfocus.com/bid/103025 https://access.redhat.com/errata/RHSA-2018:2669 https://access.redhat.com/errata/RHSA-2019:3140 https://issues.apache.org/jira/browse/THRIFT-3893 https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@3Ccommits.cassandra.apache.org3E
Attack Complexity
LOW
Privileges Required
LOW
User Interaction Required
LOW
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.8
Share on: