Back

HIGH

thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands

Published Feb 12, 2018

Description

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Affected products

Remediation

Red Hat statement

libthrift is a library used by OpenDaylight which is shipped with Red Hat OpenStack. Whilst the version of the library used contains the vulnerable code it is not used by OpenDaylight and hence not exposed. JBoss fuse 6.3 ships libthrift via insight-activemq fabric-8 profile, however the vulnerable code is not used by fabric-8 so fuse 6.3 is not affected.

Metrics

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Feb 12, 2018
Updated Sep 16, 2024
Reserved Jun 10, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jul 4, 2016
GHSA-R4M4-PMVW-M6J5