High severity8.8NVD Advisory· Published Feb 12, 2018· Updated Jun 17, 2026
CVE-2016-5397
CVE-2016-5397
Description
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/apache/thriftGo | < 0.10.0 | 0.10.0 |
Affected products
6- osv-coords4 versionspkg:apk/chainguard/cadencepkg:apk/chainguard/cadence-cassandra-toolpkg:apk/chainguard/cadence-fipspkg:golang/github.com/apache/thrift
< 1.4.0-r3+ 3 more
- (no CPE)range: < 1.4.0-r3
- (no CPE)range: < 1.4.0-r3
- (no CPE)range: < 1.4.0-r3
- (no CPE)range: < 0.10.0
- Apache Software Foundation/Apache Thriftv5Range: versions prior to 0.10.0
Patches
Vulnerability mechanics
References
10- mail-archives.apache.org/mod_mbox/thrift-user/201701.mbox/raw/%3CCANyrgvc3W%3DMJ9S-hMZecPNzxkyfgNmuSgVfW2hdDSz5ke%2BOPhQ%40mail.gmail.com%3EnvdMailing ListVendor AdvisoryWEB
- www.securityfocus.com/bid/103025nvdThird Party AdvisoryVDB Entry
- github.com/advisories/GHSA-r4m4-pmvw-m6j5ghsaADVISORY
- issues.apache.org/jira/browse/THRIFT-3893nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2016-5397ghsaADVISORY
- access.redhat.com/errata/RHSA-2018:2669nvdWEB
- access.redhat.com/errata/RHSA-2019:3140nvdWEB
- lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3@%3Ccommits.cassandra.apache.org%3EghsaWEB
- web.archive.org/web/20210124141102/http://www.securityfocus.com/bid/103025ghsaWEB
- lists.apache.org/thread.html/r4d3f1d3e333d9c2b2f6e6ae8ed8750d4de03410ac294bcd12c7eefa3%40%3Ccommits.cassandra.apache.org%3Envd
News mentions
0No linked articles in our index yet.