{"id":"CVE-2018-11798","details":"The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.","aliases":["GHSA-vx85-mj8c-4qm6"],"modified":"2026-04-10T04:04:40.533071Z","published":"2019-01-07T17:29:00.283Z","related":["CGA-8mwp-6xpm-4x8f"],"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/6e9edd282684896cedf615fb67a02bebfe6007f2d5baf03ba52e34fd%40%3Cuser.thrift.apache.org%3E"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106501"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3140"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/thrift","events":[{"introduced":"591e20f9636c37527a70dc03598218c3468a0eff"},{"last_affected":"327ebb6c2b6df8bf075da02ef45a2a034e9b79ba"}],"database_specific":{"versions":[{"introduced":"0.9.2"},{"last_affected":"0.11.0"}]}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11798.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}