apache / apache/druid

Bump Thrift library version

Open
#11,028 1 comment 1 reaction 0 assignees View on GitHub
Area - Extension Security
Dominant language
Java
Stars
14.1k
Forks
3.8k
Avg merge
2d 58m
Merged PRs (30d)
233

Description

We are using Thrift 0.13.0 which has a known security vulnerability reported in https://nvd.nist.gov/vuln/detail/CVE-2020-13949. The Thrift community recommends to upgrade its version to higher than 0.13.0.

Contributor guide

Open the contributing guide

Research direction

Start by locating the dependency declaration that pins Thrift at 0.13.0; no file or test path is specified in the issue. Check the available upgrade target and dependency validation, then confirm the project no longer uses the vulnerable version and that the existing checks pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.