First published: Fri Oct 05 2018(Updated: )
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.apache.thrift:libthrift | >=0.9.2<0.12.0 | 0.12.0 |
redhat/thrift | <0.12.0 | 0.12.0 |
Apache Thrift | >=0.9.2<=0.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11798 is considered a high severity vulnerability due to its potential for remote file access.
To mitigate CVE-2018-11798, upgrade to Apache Thrift Node.js version 0.12.0 or later.
CVE-2018-11798 affects Apache Thrift Node.js versions from 0.9.2 through 0.11.0.
CVE-2018-11798 allows remote users to access files outside of the web server's document root.
CVE-2018-11798 specifically affects the Apache Thrift library used in Node.js applications.