thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
Published Feb 12, 2018
8.8
HIGHCVSS 3.0
EPSS 6.87%
Description
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Affected products
-
- Version versions prior to 0.10.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Thrift | n/a |
|
No data.
Red Hat JBoss Data Virtualization 6.4.8
libthrift
Fixed · RHSA-2019:3140
Red Hat JBoss Fuse 7
camel
Fixed · RHSA-2018:2669
Red Hat Enterprise Linux 8
thrift
Not affected
Red Hat JBoss Fuse 6
karaf
Not affected
Red Hat JBoss Fuse Integration Service 2
libthrift
Affected
Red Hat JBoss Fuse Service Works 6
thrift
Not affected
Red Hat JBoss Operations Network 3
libthrift
Not affected
Red Hat OpenShift Enterprise 3
thrift
Not affected
Red Hat OpenStack Platform 10 (Newton)
libthrift
Will not fix
Red Hat OpenStack Platform 11 (Ocata)
libthrift
Will not fix
Red Hat OpenStack Platform 12 (Pike)
libthrift
Will not fix
Red Hat OpenStack Platform 13 (Queens)
opendaylight
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Data Virtualization 6.4.8 | libthrift | Fixed | RHSA-2019:3140 |
| Red Hat JBoss Fuse 7 | camel | Fixed | RHSA-2018:2669 |
| Red Hat Enterprise Linux 8 | thrift | Not affected | n/a |
| Red Hat JBoss Fuse 6 | karaf | Not affected | n/a |
| Red Hat JBoss Fuse Integration Service 2 | libthrift | Affected | n/a |
| Red Hat JBoss Fuse Service Works 6 | thrift | Not affected | n/a |
| Red Hat JBoss Operations Network 3 | libthrift | Not affected | n/a |
| Red Hat OpenShift Enterprise 3 | thrift | Not affected | n/a |
| Red Hat OpenStack Platform 10 (Newton) | libthrift | Will not fix | n/a |
| Red Hat OpenStack Platform 11 (Ocata) | libthrift | Will not fix | n/a |
| Red Hat OpenStack Platform 12 (Pike) | libthrift | Will not fix | n/a |
| Red Hat OpenStack Platform 13 (Queens) | opendaylight | Will not fix | n/a |
github.com/apache/thrift
Go
Introduced 0 Fixed 0.10.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/apache/thrift | 0 | 0.10.0 |
Remediation
Red Hat statement
libthrift is a library used by OpenDaylight which is shipped with Red Hat OpenStack. Whilst the version of the library used contains the vulnerable code it is not used by OpenDaylight and hence not exposed. JBoss fuse 6.3 ships libthrift via insight-activemq fabric-8 profile, however the vulnerable code is not used by fabric-8 so fuse 6.3 is not affected.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:N/AC:L/Au:S/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 6.87% (0.06873) | 93.86th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.32% (0.07318) | 93.57th | v5 (v2026.06.15) |
| Dec 6, 2025 | 22.57% (0.22566) | 95.62th | v4 (v2025.03.14) |
| Jun 22, 2025 | 8.19% (0.08192) | 91.76th | v4 (v2025.03.14) |
| Jun 19, 2025 | 12.82% (0.12818) | 93.67th | v4 (v2025.03.14) |
| May 14, 2025 | 22.04% (0.22042) | 95.44th | v4 (v2025.03.14) |
| Apr 16, 2025 | 20.48% (0.20478) | 95.16th | v4 (v2025.03.14) |
| Mar 17, 2025 | 18.76% (0.18760) | 94.80th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.53% (0.00535) | 77.94th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.53% (0.00535) | 76.47th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.53% (0.00535) | 73.61th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.74% (0.03740) | 85.11th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.74% (0.03740) | 83.58th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.74% (0.03740) | 66.73th | v2 (v2022.01.01) |
References (13)
- http://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3E mailing-listx_refsource_MLISTMailing ListVendor Advisory
- http://www.securityfocus.com/bid/103025 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/errata/RHSA-2018:2669 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2019:3140 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2016-5397 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1544620 Issue Tracking
- https://github.com/advisories/GHSA-r4m4-pmvw-m6j5 Advisory
- https://issues.apache.org/jira/browse/THRIFT-3893 x_refsource_CONFIRMVendor Advisory
- https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E mailing-listx_refsource_MLIST
- https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3E
- https://nvd.nist.gov/vuln/detail/CVE-2016-5397
- https://web.archive.org/web/20210124141102/http://www.securityfocus.com/bid/103025
- https://www.cve.org/CVERecord?id=CVE-2016-5397
Change history (0)
No recorded changes yet.