Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2016-5397

Опубликовано: 04 июл. 2016
Источник: redhat
CVSS3: 7.8
EPSS Средний

Описание

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Отчет

libthrift is a library used by OpenDaylight which is shipped with Red Hat OpenStack. Whilst the version of the library used contains the vulnerable code it is not used by OpenDaylight and hence not exposed. JBoss fuse 6.3 ships libthrift via insight-activemq fabric-8 profile, however the vulnerable code is not used by fabric-8 so fuse 6.3 is not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 8thriftNot affected
Red Hat JBoss Fuse 6karafNot affected
Red Hat JBoss Fuse Integration Service 2libthriftAffected
Red Hat JBoss Fuse Service Works 6thriftNot affected
Red Hat JBoss Operations Network 3libthriftNot affected
Red Hat OpenShift Enterprise 3thriftNot affected
Red Hat OpenStack Platform 10 (Newton)libthriftWill not fix
Red Hat OpenStack Platform 11 (Ocata)libthriftWill not fix
Red Hat OpenStack Platform 12 (Pike)libthriftWill not fix
Red Hat OpenStack Platform 13 (Queens)opendaylightWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=1544620thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands

EPSS

Процентиль: 96%
0.22566
Средний

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
nvd
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CVSS3: 8.8
debian
почти 8 лет назад

The Apache Thrift Go client library exposed the potential during code ...

CVSS3: 8.8
github
больше 3 лет назад

Apache Thrift Go Library Command Injection

EPSS

Процентиль: 96%
0.22566
Средний

7.8 High

CVSS3