Skip to content

[Security] Upgrade libthrift to 0.14.2 to address multiple CVEs (backport to branch-4.14)#2762

Merged
fpj merged 1 commit intoapache:branch-4.14from
lhotari:lh-upgrade-libthrift-4.14
Aug 13, 2021
Merged

[Security] Upgrade libthrift to 0.14.2 to address multiple CVEs (backport to branch-4.14)#2762
fpj merged 1 commit intoapache:branch-4.14from
lhotari:lh-upgrade-libthrift-4.14

Conversation

@lhotari
Copy link
Copy Markdown
Member

@lhotari lhotari commented Aug 13, 2021

Motivation

backport #2695 to branch-4.14

Fixes apache#2512

### Motivation

See apache#2512

The current libthrift version 0.12.0 has multiple vulnerabilities:
  - CVE-2019-0205 , CVE-2019-0210 , CVE-2020-13949

### Motivation

- Upgrade libthrift version to 0.14.1 and fix compilation errors
- exclude new transitive dependencies org.apache.tomcat.embed:tomcat-embed-core and javax.annotation:javax.annotation-api

Reviewers: Enrico Olivelli <eolivelli@gmail.com>, Andrey Yegorov <None>

This closes apache#2695 from lhotari/lh-upgrade-libthrift

(cherry picked from commit ea08e6d)
Copy link
Copy Markdown
Contributor

@eolivelli eolivelli left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

Copy link
Copy Markdown
Contributor

@fpj fpj left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eolivelli
Copy link
Copy Markdown
Contributor

@zymap please include this in the 4.14.2 release

@fpj fpj merged commit ff9c041 into apache:branch-4.14 Aug 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants