Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4m4-pmvw-m6j5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Apache Thrift Go Library Command Injection

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Пакеты

Наименование

github.com/apache/thrift

go
Затронутые версииВерсия исправления

<= 0.9.3

0.10.0

EPSS

Процентиль: 96%
0.22566
Средний

8.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 7.8
redhat
больше 9 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
nvd
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
debian
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code ...

EPSS

Процентиль: 96%
0.22566
Средний

8.8 High

CVSS3

Дефекты

CWE-77