Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-11798

Опубликовано: 07 янв. 2019
Источник: nvd
CVSS3: 6.5
CVSS2: 4
EPSS Низкий

Описание

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:apache:thrift:*:*:*:*:*:node.js:*:*
Версия от 0.9.2 (включая) до 0.11.0 (включая)

EPSS

Процентиль: 91%
0.04875
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-538

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 7 лет назад

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

CVSS3: 7.5
redhat
почти 8 лет назад

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

CVSS3: 6.5
debian
больше 7 лет назад

The Apache Thrift Node.js static web server in versions 0.9.2 through ...

CVSS3: 6.5
github
больше 7 лет назад

Apache Thrift Node.js static web server sandbox escape

CVSS3: 6.5
fstec
почти 8 лет назад

Уязвимость библиотеки Node.js языка описания интерфейсов Apache Thrift, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 91%
0.04875
Низкий

6.5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-538