8.8
CVSSv3

CVE-2016-5397

Published: 12/02/2018 Updated: 04/06/2020
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 801
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Vendor Advisories

Debian Bug report logs - #894577 CVE-2016-5397 Package: thrift-compiler; Maintainer for thrift-compiler is Laszlo Boszormenyi (GCS) <gcs@debianorg>; Source for thrift-compiler is src:thrift (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Sun, 1 Apr 2018 20:39:03 UTC Severity: grave Tag ...
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool Affected Apache Thrift 093 and older, Fixed in Apache Thrift 0100 ...
Synopsis Important: Red Hat JBoss Data Virtualization 648 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat JBoss Data VirtualizationRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scorin ...
Synopsis Important: Fuse 71 security update Type/Severity Security Advisory: Important Topic An update is now available for Red Hat FuseRed Hat Product Security has rated this update as having a security impact of Important A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed s ...