« List of all CVEs

CVE-2018-11798

Published: 1/7/2019 Last updated: 8/5/2024 Reserved: 6/5/2018

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

CNA assigner: apache (f0158376-9dc2-43b6-827c-5f631a4d8d09) Requested by: n/a

Opam packages affected (1)

thrift

Products affected (1)

Product Vendor Version
Apache Thrift Apache Software Foundation < 6.3.9600.21924

References (10)