← Back

CVE-2016-5397

nvd nist
Published: Feb 12, 2018Modified: Nov 21, 2024

JSON object

Loading...
8.8
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Affected (1)

Products: Apache: Thrift
1 product
Thrift
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 0.9.3

References (12)

Timeline

No history available yet.