You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The Apache thrift consists of two artifacts, libthrift and libfb303. Vulnerabilities have been reported in libthrift version 0.9.3 to 0.13.0. Newer versions have been provided, fixing those issues. But since no vulnerabilities have been found in libfb303, its version stays at 0.9.3. It is problematic that the two artifacts share the CPE.
Thrift was first developed by Facebook, but later was taken over by Apache.
Apart from the mentioned CPE, it also matches cpe:2.3:a:facebook:thrift:0.9.3:*:*:*:*:*:*:*, i.e. the old Facebook one. This is definitely wrong, since the group ID clearly identifies the artifact as the Apache one.
The text was updated successfully, but these errors were encountered:
Package URl
pkg:maven/org.apache.thrift/libfb303@0.9.3
CPE
cpe:2.3:a:apache:thrift:0.9.3:*:*:*:*:*:*:*
CVE
No response
ODC Integration
{"label"=>"Maven Plugin"}
ODC Version
8.3.1
Description
The Apache thrift consists of two artifacts,
libthrift
andlibfb303
. Vulnerabilities have been reported inlibthrift
version 0.9.3 to 0.13.0. Newer versions have been provided, fixing those issues. But since no vulnerabilities have been found in libfb303, its version stays at 0.9.3. It is problematic that the two artifacts share the CPE.Thrift was first developed by Facebook, but later was taken over by Apache.
Apart from the mentioned CPE, it also matches
cpe:2.3:a:facebook:thrift:0.9.3:*:*:*:*:*:*:*
, i.e. the old Facebook one. This is definitely wrong, since the group ID clearly identifies the artifact as the Apache one.The text was updated successfully, but these errors were encountered: