Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ4ODUtbWo4Yy00cW02
Apache Thrift Node.js static web server sandbox escape
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
Permalink: https://github.com/advisories/GHSA-vx85-mj8c-4qm6JSON: https://advisories.ecosyste.ms/api/v1/advisories/MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZ4ODUtbWo4Yy00cW02
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 6 years ago
Updated: about 1 year ago
CVSS Score: 6.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-vx85-mj8c-4qm6, CVE-2018-11798
References:
- https://nvd.nist.gov/vuln/detail/CVE-2018-11798
- https://access.redhat.com/errata/RHSA-2019:1545
- https://access.redhat.com/errata/RHSA-2019:3140
- https://github.com/advisories/GHSA-vx85-mj8c-4qm6
- https://lists.apache.org/thread.html/6e9edd282684896cedf615fb67a02bebfe6007f2d5baf03ba52e34fd@%3Cuser.thrift.apache.org%3E
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
- https://github.com/apache/thrift/pull/1606
- https://github.com/apache/thrift/commit/2a2b72f6c8aef200ecee4984f011e06052288ff2
- https://issues.apache.org/jira/browse/THRIFT-4647
- https://web.archive.org/web/20200227094236/http://www.securityfocus.com/bid/106501
Blast Radius: 27.0
Affected Packages
maven:org.apache.thrift:libthrift
Dependent packages: 1,290Dependent repositories: 14,005
Downloads:
Affected Version Ranges: >= 0.9.2, < 0.12.0
Fixed in: 0.12.0
All affected versions: 0.9.2, 0.9.3, 0.10.0, 0.11.0
All unaffected versions: 0.6.1, 0.7.0, 0.8.0, 0.9.0, 0.9.1, 0.12.0, 0.13.0, 0.14.0, 0.14.1, 0.14.2, 0.15.0, 0.16.0, 0.17.0, 0.18.0, 0.18.1, 0.19.0, 0.20.0, 0.21.0