[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2020-06-12 Thread Jens Geyer (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17134503#comment-17134503 ] Jens Geyer commented on THRIFT-4928: TTransportExceptions never leave the machine where they are

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2020-06-11 Thread Jens Geyer (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17132975#comment-17132975 ] Jens Geyer commented on THRIFT-4928: Thank you Max, fully agree. The unquestioned and unreflected

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2020-06-10 Thread Max (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17132798#comment-17132798 ] Max commented on THRIFT-4928: - Just because a tool reported an issue – doesn't immediately mean there's a

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-10-16 Thread Qinghui Xu (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16953108#comment-16953108 ] Qinghui Xu commented on THRIFT-4928: It seems to me there are a lot of duplicated tickets #

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-18 Thread Qinghui Xu (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16932758#comment-16932758 ] Qinghui Xu commented on THRIFT-4928: [~jensg] In the first place, these numbers should not be

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-18 Thread Jens Geyer (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16932717#comment-16932717 ] Jens Geyer commented on THRIFT-4928: [~q.xu] I have my own theory about that, but I certainly will

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-18 Thread Qinghui Xu (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16932622#comment-16932622 ] Qinghui Xu commented on THRIFT-4928: [~xiaoqin.fu] [~pengzhouhu] Why do you think putting the byte

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-07 Thread Jens Geyer (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16924873#comment-16924873 ] Jens Geyer commented on THRIFT-4928: let alone it's not only against the [established set of rules

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-07 Thread pengzhouhu (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16924869#comment-16924869 ] pengzhouhu commented on THRIFT-4928: [~jensg][~xiaoqin.fu] i think push a public CVE before talk

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-07 Thread Jens Geyer (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16924825#comment-16924825 ] Jens Geyer commented on THRIFT-4928: I'm not sure. I mean, we can (probably should) remove the

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-07 Thread Jens Geyer (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16924824#comment-16924824 ] Jens Geyer commented on THRIFT-4928: The question re (5) was that YOU made a claim and asked

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-09-05 Thread xiaoqin.fu (Jira)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16923912#comment-16923912 ] xiaoqin.fu commented on THRIFT-4928: 1) I think that pull requests are also ok. 2) The problem,

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-08-18 Thread Jens Geyer (JIRA)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16910015#comment-16910015 ] Jens Geyer commented on THRIFT-4928: I may overlook sth, therefore I ask you to add some substance

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-08-17 Thread xiaoqin.fu (JIRA)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16909836#comment-16909836 ] xiaoqin.fu commented on THRIFT-4928: 2) The problem is found in a taint path. 3) I think that we can

[jira] [Commented] (THRIFT-4928) Sensitive information about expected and actual reading lengths (len, got) is leaked from TIOStreamTransport to TTransport through a TTransportException

2019-08-17 Thread Jens Geyer (JIRA)
[ https://issues.apache.org/jira/browse/THRIFT-4928?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16909775#comment-16909775 ] Jens Geyer commented on THRIFT-4928: 1) Why do we need to start the process with an CVE? 2) What is