Lucene search

K
cvelistApacheCVELIST:CVE-2016-5397
HistoryJan 13, 2017 - 12:00 a.m.

CVE-2016-5397

2017-01-1300:00:00
apache
www.cve.org
1

8.4 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.2%

The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.

CNA Affected

[
  {
    "product": "Apache Thrift",
    "vendor": "Apache Software Foundation",
    "versions": [
      {
        "status": "affected",
        "version": "versions prior to 0.10.0"
      }
    ]
  }
]

8.4 High

AI Score

Confidence

High

0.005 Low

EPSS

Percentile

77.2%