{"id":"PYSEC-2018-78","details":"uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.","aliases":["CVE-2018-7490","GHSA-h2vm-c85r-5vh5"],"modified":"2026-06-10T17:02:45.841314903Z","published":"2018-02-26T22:29:00Z","references":[{"type":"WEB","url":"https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.17.html"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/44223/"},{"type":"ADVISORY","url":"https://www.debian.org/security/2018/dsa-4142"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-h2vm-c85r-5vh5"}],"affected":[{"package":{"name":"uwsgi","ecosystem":"PyPI","purl":"pkg:pypi/uwsgi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.17"}]}],"versions":["1.4.10","1.4.9","1.9","1.9.1","1.9.10","1.9.11","1.9.12","1.9.13","1.9.14","1.9.15","1.9.16","1.9.17","1.9.17.1","1.9.18","1.9.18.1","1.9.18.2","1.9.19","1.9.2","1.9.20","1.9.21","1.9.21.1","1.9.3","1.9.4","1.9.5","1.9.6","1.9.7","1.9.8","1.9.9","2.0","2.0.1","2.0.10","2.0.11","2.0.11.1","2.0.11.2","2.0.12","2.0.13","2.0.13.1","2.0.14","2.0.15","2.0.16","2.0.2","2.0.3","2.0.4","2.0.5","2.0.5.1","2.0.6","2.0.7","2.0.8","2.0.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/uwsgi/PYSEC-2018-78.yaml"}}],"schema_version":"1.7.5"}