Skip to content

[Security] Upgrade libthrift to 0.14.2 to address multiple CVEs (backport to branch-4.14) - #2762

Merged
fpj merged 1 commit into
apache:branch-4.14from
lhotari:lh-upgrade-libthrift-4.14
Aug 13, 2021
Merged

fpj merged 1 commit into
apache:branch-4.14from
lhotari:lh-upgrade-libthrift-4.14

Conversation

@lhotari

@lhotari lhotari commented Aug 13, 2021

Copy link
Copy Markdown
Member

Motivation

backport #2695 to branch-4.14

Fixes apache#2512

### Motivation

See apache#2512

The current libthrift version 0.12.0 has multiple vulnerabilities:
  - CVE-2019-0205 , CVE-2019-0210 , CVE-2020-13949

### Motivation

- Upgrade libthrift version to 0.14.1 and fix compilation errors
- exclude new transitive dependencies org.apache.tomcat.embed:tomcat-embed-core and javax.annotation:javax.annotation-api

Reviewers: Enrico Olivelli <[email protected]>, Andrey Yegorov <None>

This closes apache#2695 from lhotari/lh-upgrade-libthrift

(cherry picked from commit ea08e6d)

@eolivelli eolivelli left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@fpj fpj left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@eolivelli

Copy link
Copy Markdown
Contributor

@zymap please include this in the 4.14.2 release

@fpj
fpj merged commit ff9c041 into apache:branch-4.14 Aug 13, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants