[jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1

2019-07-18 Thread David Lavati (JIRA)


 [ 
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

David Lavati updated HIVE-21173:

Summary: Upgrade Apache Thrift to 0.9.3-1  (was: Upgrade to the latest 
release of Apache Thrift)

> Upgrade Apache Thrift to 0.9.3-1
> 
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
>  Issue Type: Bug
>  Components: Thrift API
>Reporter: James E. King III
>Assignee: David Lavati
>Priority: Major
>
> The project currently depends on libthrift-0.9.3, however thrift released 
> 0.12.0 on 2019-JAN-04.This release includes a security fix for 
> THRIFT-4506 (CVE-2018-1320).  Updating thrift to the latest version will 
> remove that vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer.  
> fb303 is contributed code (in '/contrib') and it has not been maintained.



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)


[jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1

2019-07-18 Thread ASF GitHub Bot (JIRA)


 [ 
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

ASF GitHub Bot updated HIVE-21173:
--
Labels: pull-request-available  (was: )

> Upgrade Apache Thrift to 0.9.3-1
> 
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
>  Issue Type: Bug
>  Components: Thrift API
>Reporter: James E. King III
>Assignee: David Lavati
>Priority: Major
>  Labels: pull-request-available
>
> The project currently depends on libthrift-0.9.3, however thrift released 
> 0.12.0 on 2019-JAN-04.This release includes a security fix for 
> THRIFT-4506 (CVE-2018-1320).  Updating thrift to the latest version will 
> remove that vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer.  
> fb303 is contributed code (in '/contrib') and it has not been maintained.



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)


[jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1

2019-07-18 Thread David Lavati (JIRA)


 [ 
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

David Lavati updated HIVE-21173:

Attachment: HIVE-21173.01.patch
Status: Patch Available  (was: Reopened)

> Upgrade Apache Thrift to 0.9.3-1
> 
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
>  Issue Type: Bug
>  Components: Thrift API
>Reporter: James E. King III
>Assignee: David Lavati
>Priority: Major
>  Labels: pull-request-available
> Attachments: HIVE-21173.01.patch
>
>  Time Spent: 10m
>  Remaining Estimate: 0h
>
> The project currently depends on libthrift-0.9.3, however thrift released 
> 0.12.0 on 2019-JAN-04.This release includes a security fix for 
> THRIFT-4506 (CVE-2018-1320).  Updating thrift to the latest version will 
> remove that vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer.  
> fb303 is contributed code (in '/contrib') and it has not been maintained.



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)


[jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1

2019-07-18 Thread David Lavati (JIRA)


 [ 
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

David Lavati updated HIVE-21173:

Description: 
The project currently depends on libthrift-0.9.3, however thrift released 
0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506 
(CVE-2018-1320). Updating thrift to the latest version will remove that 
vulnerability.

Also note the Apache Thrift project does not publish "libfb303" any longer. 
fb303 is contributed code (in '/contrib') and it has not been maintained.

 

Ps.: 0.9.3.1 also addresses the CVE, see THRIFT-4506

  was:
The project currently depends on libthrift-0.9.3, however thrift released 
0.12.0 on 2019-JAN-04.This release includes a security fix for THRIFT-4506 
(CVE-2018-1320).  Updating thrift to the latest version will remove that 
vulnerability.

Also note the Apache Thrift project does not publish "libfb303" any longer.  
fb303 is contributed code (in '/contrib') and it has not been maintained.


> Upgrade Apache Thrift to 0.9.3-1
> 
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
>  Issue Type: Bug
>  Components: Thrift API
>Reporter: James E. King III
>Assignee: David Lavati
>Priority: Major
>  Labels: pull-request-available
> Attachments: HIVE-21173.01.patch
>
>  Time Spent: 10m
>  Remaining Estimate: 0h
>
> The project currently depends on libthrift-0.9.3, however thrift released 
> 0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506 
> (CVE-2018-1320). Updating thrift to the latest version will remove that 
> vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer. 
> fb303 is contributed code (in '/contrib') and it has not been maintained.
>  
> Ps.: 0.9.3.1 also addresses the CVE, see THRIFT-4506



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)


[jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1

2019-07-24 Thread Laszlo Bodor (JIRA)


 [ 
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Laszlo Bodor updated HIVE-21173:

Fix Version/s: 4.0.0

> Upgrade Apache Thrift to 0.9.3-1
> 
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
>  Issue Type: Bug
>  Components: Thrift API
>Reporter: James E. King III
>Assignee: David Lavati
>Priority: Major
>  Labels: pull-request-available
> Fix For: 4.0.0
>
> Attachments: HIVE-21173.01.patch
>
>  Time Spent: 40m
>  Remaining Estimate: 0h
>
> The project currently depends on libthrift-0.9.3, however thrift released 
> 0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506 
> (CVE-2018-1320). Updating thrift to the latest version will remove that 
> vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer. 
> fb303 is contributed code (in '/contrib') and it has not been maintained.
>  
> Ps.: 0.9.3.1 also addresses the CVE, see THRIFT-4506



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)


[jira] [Updated] (HIVE-21173) Upgrade Apache Thrift to 0.9.3-1

2019-07-24 Thread Laszlo Bodor (JIRA)


 [ 
https://issues.apache.org/jira/browse/HIVE-21173?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Laszlo Bodor updated HIVE-21173:

Resolution: Fixed
Status: Resolved  (was: Patch Available)

> Upgrade Apache Thrift to 0.9.3-1
> 
>
> Key: HIVE-21173
> URL: https://issues.apache.org/jira/browse/HIVE-21173
> Project: Hive
>  Issue Type: Bug
>  Components: Thrift API
>Reporter: James E. King III
>Assignee: David Lavati
>Priority: Major
>  Labels: pull-request-available
> Attachments: HIVE-21173.01.patch
>
>  Time Spent: 40m
>  Remaining Estimate: 0h
>
> The project currently depends on libthrift-0.9.3, however thrift released 
> 0.12.0 on 2019-JAN-04. This release includes a security fix for THRIFT-4506 
> (CVE-2018-1320). Updating thrift to the latest version will remove that 
> vulnerability.
> Also note the Apache Thrift project does not publish "libfb303" any longer. 
> fb303 is contributed code (in '/contrib') and it has not been maintained.
>  
> Ps.: 0.9.3.1 also addresses the CVE, see THRIFT-4506



--
This message was sent by Atlassian JIRA
(v7.6.14#76016)