Hi, Here are some vulnerabilities from Apache Thri...
# general
t
Hi, Here are some vulnerabilities from Apache Thrift 0.14.1. Looks like they are all from Thrift Server side. Thanks.
m
It looks like Apache Thrift is lagging the fixes available in Facebook Thrift. I am not sure they've patched any of these.
t
Thanks @Mike Myers, Is there a way for accessing the updated version of Facebook Thrift? Apache Thrift repo doesn’t even allow to file an issue. Thanks!
m
Their issues are tracked at their Apache page, but I couldn't find discussions of any of these
Is this a report from Black Duck software?
https://github.com/osquery/osquery/issues/7104 I opened an issue here for us to evaluate
t
yes, we have regular scanning for security issues internally using black duck.
z
FWIW osquery's Thrift server listens on a socket (POSIX) or named pipe (Windows) that is permissioned to allow only root users to access it. So I'm not sure vulnerabilities in the server would be worth exploiting (since the user would already have root).
m
That's true (now — until recently on Windows osquery didn't lock down the Thrift pipe but now it does)