Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-r4m4-pmvw-m6j5

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Apache Thrift Go Library Command Injection

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Пакеты

Наименование

github.com/apache/thrift

go
Затронутые версииВерсия исправления

<= 0.9.3

0.10.0

EPSS

Процентиль: 94%
0.07061
Низкий

8.8 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 7.8
redhat
около 10 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
nvd
больше 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
debian
больше 8 лет назад

The Apache Thrift Go client library exposed the potential during code ...

EPSS

Процентиль: 94%
0.07061
Низкий

8.8 High

CVSS3

Дефекты

CWE-77