[
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
David Lavati updated HIVE-21173:
--------------------------------
Description:
The project currently depends on libthrift-0.9.3, however thrift released
0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506
(CVE-2018-1320). Updating thrift to the latest version will remove that
vulnerability.
Also note the Apache Thrift project does not publish "libfb303" any longer.
fb303 is contributed code (in '/contrib') and it has not been maintained.
Ps.: 0.9.3.1 also addresses the CVE, see THRIFT-4506
was:
The project currently depends on libthrift-0.9.3, however thrift released
0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506
(CVE-2018-1320). Updating thrift to the latest version will remove that
vulnerability.
Also note the Apache Thrift project does not publish "libfb303" any longer.
fb303 is contributed code (in '/contrib') and it has not been maintained.
> Upgrade Apache Thrift to 0.9.3-1
> --------------------------------
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
> Issue Type: Bug
> Components: Thrift API
> Reporter: James E. King III
> Assignee: David Lavati
> Priority: Major
> Labels: pull-request-available
> Attachments: HIVE-21173.01.patch
>
> Time Spent: 10m
> Remaining Estimate: 0h
>
> The project currently depends on libthrift-0.9.3, however thrift released
> 0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506
> (CVE-2018-1320). Updating thrift to the latest version will remove that
> vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer.
> fb303 is contributed code (in '/contrib') and it has not been maintained.
>
> Ps.: 0.9.3.1 also addresses the CVE, see THRIFT-4506
--
This message was sent by Atlassian JIRA
(v7.6.14#76016)