Uploaded image for project: 'HBase'
  1. HBase
  2. HBASE-21791

Upgrade thrift dependency to 0.12.0

Log workAgile BoardRank to TopRank to BottomAttach filesAttach ScreenshotBulk Copy AttachmentsBulk Move AttachmentsVotersWatch issueWatchersCreate sub-taskConvert to sub-taskMoveLinkCloneLabelsUpdate Comment AuthorReplace String in CommentUpdate Comment VisibilityDelete Comments
    XMLWordPrintableJSON

Details

    • Task
    • Status: Resolved
    • Blocker
    • Resolution: Fixed
    • 3.0.0-alpha-1, 1.5.0, 1.3.3, 2.2.0, 1.4.9, 2.1.2, 1.2.10, 2.0.4
    • 3.0.0-alpha-1, 1.5.0, 2.2.0, 2.1.3, 2.0.5, 2.3.0
    • Thrift
    • None
    • Reviewed
    • Hide
      IMPORTANT: Due to security issues, all users who use hbase thrift should avoid using releases which do not have this fix.

      The effect releases are:
      2.1.x: 2.1.2 and below
      2.0.x: 2.0.4 and below
      1.x: 1.4.x and below

      If you are using the effect releases above, please consider upgrading to a newer release ASAP.
      Show
      IMPORTANT: Due to security issues, all users who use hbase thrift should avoid using releases which do not have this fix. The effect releases are: 2.1.x: 2.1.2 and below 2.0.x: 2.0.4 and below 1.x: 1.4.x and below If you are using the effect releases above, please consider upgrading to a newer release ASAP.

    Description

      As somebody have already known, that there is a CVE for thrift from 0.5.0 to 0.11.0.

      https://nvd.nist.gov/vuln/detail/CVE-2018-1320

      As the CVE is already public, let's upgrade our thrift dependency and release new versions ASAP.

      Attachments

        Issue Links

        Activity

          This comment will be Viewable by All Users Viewable by All Users
          Cancel

          People

            zhangduo Duo Zhang Assign to me
            zhangduo Duo Zhang
            Votes:
            0 Vote for this issue
            Watchers:
            8 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved:

              Slack

                Issue deployment