Описание
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
A flaw was found in the Node.js static web server in Apache Thrift, where it allowed a remote user to access files outside of the set web servers' docroot path. An attacker could use this flaw to possibly access unauthorized files and sensitive information.
Отчет
OpenStack and OpenDaylight: The Java implementation of thrift is used in OpenDaylight by parts of the vpnservice functionality. This flaw refers to the JavaScript (node.js) server for Thrift, which is not used or shipped with OpenDaylight or any other part of Red Hat OpenStack Platform.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat JBoss Fuse Service Works 6 | thrift | Out of support scope | ||
| Red Hat JBoss Operations Network 3 | libthrift | Will not fix | ||
| Red Hat OpenShift Application Runtimes | libthrift | Affected | ||
| Red Hat OpenShift Container Platform 3.10 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 3.11 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 3.4 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 3.5 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 3.6 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 3.7 | thrift | Not affected | ||
| Red Hat OpenShift Container Platform 3.9 | thrift | Not affected |
Показывать по
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
The Apache Thrift Node.js static web server in versions 0.9.2 through ...
Apache Thrift Node.js static web server sandbox escape
Уязвимость библиотеки Node.js языка описания интерфейсов Apache Thrift, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации
7.5 High
CVSS3