Details
Description
As somebody have already known, that there is a CVE for thrift from 0.5.0 to 0.11.0.
https://nvd.nist.gov/vuln/detail/CVE-2018-1320
As the CVE is already public, let's upgrade our thrift dependency and release new versions ASAP.
Attachments
Attachments
Issue Links
- is related to
-
HBASE-24148 Upgrade Thrift to 0.13.0: 0.12.0 has outstanding CVEs.
- Resolved
- relates to
-
HBASE-22058 upgrade thrift dependency to 0.9.3.1 on branches 1.4, 1.3 and 1.2
- Resolved