[ https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16888025#comment-16888025 ]
Hive QA commented on HIVE-21173: -------------------------------- Here are the results of testing the latest attachment: https://issues.apache.org/jira/secure/attachment/12975153/HIVE-21173.01.patch {color:red}ERROR:{color} -1 due to no test(s) being added or modified. {color:green}SUCCESS:{color} +1 due to 16681 tests passed Test results: https://builds.apache.org/job/PreCommit-HIVE-Build/18084/testReport Console output: https://builds.apache.org/job/PreCommit-HIVE-Build/18084/console Test logs: http://104.198.109.242/logs/PreCommit-HIVE-Build-18084/ Messages: {noformat} Executing org.apache.hive.ptest.execution.TestCheckPhase Executing org.apache.hive.ptest.execution.PrepPhase Executing org.apache.hive.ptest.execution.YetusPhase Executing org.apache.hive.ptest.execution.ExecutionPhase Executing org.apache.hive.ptest.execution.ReportingPhase {noformat} This message is automatically generated. ATTACHMENT ID: 12975153 - PreCommit-HIVE-Build > Upgrade Apache Thrift to 0.9.3-1 > -------------------------------- > > Key: HIVE-21173 > URL: https://issues.apache.org/jira/browse/HIVE-21173 > Project: Hive > Issue Type: Bug > Components: Thrift API > Reporter: James E. King III > Assignee: David Lavati > Priority: Major > Labels: pull-request-available > Attachments: HIVE-21173.01.patch > > Time Spent: 10m > Remaining Estimate: 0h > > The project currently depends on libthrift-0.9.3, however thrift released > 0.12.0 on 2019-JAN-04. This release includes a security fix for > THRIFT-4506 (CVE-2018-1320). Updating thrift to the latest version will > remove that vulnerability. > Also note the Apache Thrift project does not publish "libfb303" any longer. > fb303 is contributed code (in '/contrib') and it has not been maintained. -- This message was sent by Atlassian JIRA (v7.6.14#76016)