CVE-2016-5397
published 2018-02-12CVE-2016-5397: The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected…
PriorityP356high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
EPSS
7.06%
93.5th percentile
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | thrift | <= 0.9.3 | — |
| apache_software_foundation | apache_thrift | — | — |
| debian | thrift | < thrift 0.11.0-3 (bookworm) | thrift 0.11.0-3 (bookworm) |
| thrift | >= 0 < 0.11.0-3 | 0.11.0-3 | |
| thrift | >= 0 < 0.11.0-3 | 0.11.0-3 | |
| thrift | >= 0 < 0.11.0-3 | 0.11.0-3 | |
| thrift | >= 0 < 0.11.0-3 | 0.11.0-3 | |
| github.com | apache_thrift | >= 0 < 0.10.0 | 0.10.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →Monitor for command injection via crafted Thrift service names passed to the Go code generator — the file_path parameter in format_go_output() is derived from the service name and passed unsanitized to an external formatting tool. ↗
- →Flag use of Apache Thrift versions 0.9.3 and older in Go code-generation pipelines; the vulnerability is fixed in 0.10.0. ↗
- →Audit any framework that accepts user-controlled service names and passes them to the Apache Thrift Go client library code generator (t_go_generator.cc:format_go_output()) for potential command injection. ↗
- ·libthrift shipped with OpenDaylight (Red Hat OpenStack) contains the vulnerable code but it is not invoked by OpenDaylight, so those deployments are not exposed. ↗
- ·JBoss Fuse 6.3 ships libthrift via the insight-activemq fabric-8 profile, but the vulnerable code path is not exercised by fabric-8. ↗
- ·Exploitation requires the attacker to be able to supply a service name to a framework that invokes the Thrift Go code generator — this is a local/code-generation-time attack surface, not a runtime network attack. ↗
CVSS provenance
nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8LOW
vendor_redhat8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
vendor_redhat·2016-07-04·CVSS 8.8
CVE-2016-5397 [HIGH] CWE-78 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Statement: libthrift is a library used by OpenDaylight which is shipped with Red Hat OpenStack. Whilst the version of the library used contains the vulnerable code it is not used by OpenDaylight and hence not exposed.
JBoss fuse 6.3 ships libthrift via insight-activemq fabric-8 profile, however the vulnerable code is not used by fabric-8 so fuse 6.3 is not affected.
Package: thrift (Red Hat Enterprise Linux 8) - Not affected
Packa
Debian
CVE-2016-5397: thrift - The Apache Thrift Go client library exposed the potential during code generation...
vendor_debian·2016·CVSS 8.8
CVE-2016-5397 [HIGH] CVE-2016-5397: thrift - The Apache Thrift Go client library exposed the potential during code generation...
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Scope: local
bookworm: resolved (fixed in 0.11.0-3)
bullseye: resolved (fixed in 0.11.0-3)
forky: resolved (fixed in 0.11.0-3)
sid: resolved (fixed in 0.11.0-3)
trixie: resolved (fixed in 0.11.0-3)
GHSA
Apache Thrift Go Library Command Injection
ghsa·2022-05-13
CVE-2016-5397 [HIGH] CWE-77 Apache Thrift Go Library Command Injection
Apache Thrift Go Library Command Injection
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
OSV
Apache Thrift Go Library Command Injection
osv·2022-05-13
CVE-2016-5397 [HIGH] Apache Thrift Go Library Command Injection
Apache Thrift Go Library Command Injection
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
OSV
CVE-2016-5397: The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool
osv·2018-02-12·CVSS 8.8
CVE-2016-5397 [HIGH] CVE-2016-5397: The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-5397 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
bugzilla·2018-02-13·CVSS 8.8
CVE-2016-5397 [HIGH] CVE-2016-5397 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
CVE-2016-5397 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands
Improper validation of the file_path argument in t_go_generator.cc:format_go_output() of the Apache Thrift Go client library can allow an attacker to execute arbitrary commands.
The file_path parameter is derived from the service name. If an attacker can provide a service name to a framework invoking Thrift, the attacker could craft the name in a way leading to arbitrary commands being executed.
This affects versions before Apache Thrift 0.10.0.
Upstream Advisory:
http://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3E
Upstream Issue:
ht
Bugzilla
CVE-2016-5397 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands [epel-all]
bugzilla·2018-02-13·CVSS 8.8
CVE-2016-5397 [HIGH] CVE-2016-5397 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands [epel-all]
CVE-2016-5397 thrift: Improper file path sanitization in t_go_generator.cc:format_go_output() of the go client library can allow an attacker to inject commands [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of epel-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM cha
http://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3Ehttp://www.securityfocus.com/bid/103025https://access.redhat.com/errata/RHSA-2018:2669https://access.redhat.com/errata/RHSA-2019:3140https://issues.apache.org/jira/browse/THRIFT-3893https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3Ehttp://mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3Ehttp://www.securityfocus.com/bid/103025https://access.redhat.com/errata/RHSA-2018:2669https://access.redhat.com/errata/RHSA-2019:3140https://issues.apache.org/jira/browse/THRIFT-3893https://lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3E
2018-02-12
Published