hive-issues mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "David Lavati (JIRA)" <j...@apache.org>
Subject [jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1
Date Thu, 18 Jul 2019 12:24:00 GMT

     [ https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]

David Lavati updated HIVE-21173:
--------------------------------
    Attachment: HIVE-21173.01.patch
        Status: Patch Available  (was: Reopened)

> Upgrade Apache Thrift to 0.9.3-1
> --------------------------------
>
>                 Key: HIVE-21173
>                 URL: https://issues.apache.org/jira/browse/HIVE-21173
>             Project: Hive
>          Issue Type: Bug
>          Components: Thrift API
>            Reporter: James E. King III
>            Assignee: David Lavati
>            Priority: Major
>              Labels: pull-request-available
>         Attachments: HIVE-21173.01.patch
>
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> The project currently depends on libthrift-0.9.3, however thrift released 0.12.0 on 2019-JAN-04.
   This release includes a security fix for THRIFT-4506 (CVE-2018-1320).  Updating thrift
to the latest version will remove that vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer.  fb303 is
contributed code (in '/contrib') and it has not been maintained.



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)

Mime
View raw message