You are viewing a plain text version of this content. The canonical link for it is here.
Posted to issues@hive.apache.org by "David Lavati (JIRA)" <ji...@apache.org> on 2019/07/18 11:34:00 UTC

[jira] [Reopened] (HIVE-21173) Upgrade to the latest release of Apache Thrift

     [ https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]

David Lavati reopened HIVE-21173:
---------------------------------
      Assignee: David Lavati

I'm reopening this, to apply 0.9.3-1, which addressed the mentioned CVE.

HIVE-21000 will eventually surpass this, but we're kind of blocked there without a new accumulo release.

> Upgrade to the latest release of Apache Thrift
> ----------------------------------------------
>
>                 Key: HIVE-21173
>                 URL: https://issues.apache.org/jira/browse/HIVE-21173
>             Project: Hive
>          Issue Type: Bug
>          Components: Thrift API
>            Reporter: James E. King III
>            Assignee: David Lavati
>            Priority: Major
>
> The project currently depends on libthrift-0.9.3, however thrift released 0.12.0 on 2019-JAN-04.    This release includes a security fix for THRIFT-4506 (CVE-2018-1320).  Updating thrift to the latest version will remove that vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer.  fb303 is contributed code (in '/contrib') and it has not been maintained.



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)