CVE-2016-5397

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
12/02/2018
Last modified:
07/11/2023

Description

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:thrift:*:*:*:*:*:*:*:* 0.9.3 (including)