CVE-2018-7490: Path Traversal
uWSGI before 2.0.17 mishandles a DOCUMENTROOT check during use of the --php-docroot option, allowing directory traversal.
Other sources
uWSGI before 2.0.17 mishandles a DOCUMENTROOT check during use of the --php-docroot option, allowing directory traversal.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/uwsgito a version that resolves this vulnerability.Fixed in 2.0.18-1Fixed in 2.0.19.1-7.1Fixed in 2.0.21-5.1Fixed in 2.0.22-4 - Upgrade
Upgrade
pip/uWSGIto a version that resolves this vulnerability.Fixed in 2.0.17
Event History
Frequently Asked Questions
What is the vulnerability ID for this uWSGI vulnerability?
The vulnerability ID for this uWSGI vulnerability is CVE-2018-7490.
What is the severity level of CVE-2018-7490?
The severity level of CVE-2018-7490 is high.
How does uWSGI before 2.0.17 mishandle a DOCUMENT_ROOT check?
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
Which versions of uWSGI are affected by this vulnerability?
Versions 2.0.17 and earlier of uWSGI are affected by this vulnerability.
How can I fix this vulnerability in uWSGI?
To fix this vulnerability in uWSGI, update to version 2.0.18-1 or later.