James E. King III created HIVE-21173: ----------------------------------------
Summary: Upgrade to the latest release of Apache Thrift Key: HIVE-21173 URL: https://issues.apache.org/jira/browse/HIVE-21173 Project: Hive Issue Type: Bug Components: Thrift API Reporter: James E. King III The project currently depends on libthrift-0.9.3, however thrift released 0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506 (CVE-2018-1320). Updating thrift to the latest version will remove that vulnerability. Also note the Apache Thrift project does not publish "libfb303" any longer. fb303 is contributed code (in '/contrib') and it has not been maintained. -- This message was sent by Atlassian JIRA (v7.6.3#76005)