{"id":"GHSA-h2vm-c85r-5vh5","summary":"uWSGI Directory Traversal vulnerability","details":"uWSGI before 2.0.17 mishandles a `DOCUMENT_ROOT` check during use of the `--php-docroot` option, allowing directory traversal.","aliases":["CVE-2018-7490","PYSEC-2018-78"],"modified":"2024-11-18T23:02:33.020001Z","published":"2022-05-14T03:35:52Z","database_specific":{"nvd_published_at":"2018-02-26T22:29:00Z","cwe_ids":["CWE-22"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-04-29T11:13:39Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-7490"},{"type":"WEB","url":"https://github.com/unbit/uwsgi/commit/0a480f435ea6feb63deb410ad2bf376ed3f05f8a"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/uwsgi/PYSEC-2018-78.yaml"},{"type":"PACKAGE","url":"https://github.com/unbit/uwsgi"},{"type":"WEB","url":"https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.17.html"},{"type":"WEB","url":"https://www.debian.org/security/2018/dsa-4142"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/44223"}],"affected":[{"package":{"name":"uwsgi","ecosystem":"PyPI","purl":"pkg:pypi/uwsgi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.17"}]}],"versions":["1.4.10","1.4.9","1.9","1.9.1","1.9.10","1.9.11","1.9.12","1.9.13","1.9.14","1.9.15","1.9.16","1.9.17","1.9.17.1","1.9.18","1.9.18.1","1.9.18.2","1.9.19","1.9.2","1.9.20","1.9.21","1.9.21.1","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9","2.0","2.0.1","2.0.10","2.0.11","2.0.11.1","2.0.11.2","2.0.12","2.0.13","2.0.13.1","2.0.14","2.0.15","2.0.16","2.0.2","2.0.3","2.0.4","2.0.5","2.0.5.1","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-h2vm-c85r-5vh5/GHSA-h2vm-c85r-5vh5.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N"}]}