glaubitz commented on PR #3220: URL: https://github.com/apache/thrift/pull/3220#issuecomment-4377286118
> The commits are not marked primarily for the [technical reason that it would break git history](https://www.apache.org/security/committers.html#complete). Also, binding a CVE to single commit ids is not always possible. Finally, there are opinions on both end of the spectrum why this is a great or a bad idea (pick your side) at all. The CVE you mentioned is fixed in 0.23.0 and master. The problem is that enterprise distributions can't just easily update to the latest and greatest upstream versions. We have to cherry-pick patches and that usually works for 99% of the upstream projects. I'm quite surprised that the Apache Foundation handles it differently and expects downstream just to keep updating the whole software package to fix a CVE. I'll try to find the commit myself then. It fixes a buffer overflow, so it should be a single identifiable patch. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
