Skip to content

Upgrade Thrift dependency in broker to solve CVE-2019-0210, CVE-2019-0205 and CVE-2020-13949 #9248

@fmiguelez

Description

@fmiguelez

Library from Apache Thrift (libthrift-0.12.jar) used by Apache Pulsar Broker is affected by two high risk vulnerabilities:
CVE-2019-0210 and CVE-2019-0205

These vulnerabilities are solved by version 0.13.

Update 2021/02/19

New vulnerability CVE-2020-13949 has been published affecting libthrift up to (including) version 0.13. Version 0.14 seems to solve the issue.

Metadata

Metadata

Assignees

No one assigned

    Labels

    lifecycle/staletype/enhancementThe enhancements for the existing features or docs. e.g. reduce memory usage of the delayed messages

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions