Back

HIGH

thrift: Improper Access Control grants access to files outside the webservers docroot path

Published Jan 7, 2019

Description

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

Affected products

Remediation

Red Hat statement

OpenStack and OpenDaylight: The Java implementation of thrift is used in OpenDaylight by parts of the vpnservice functionality. This flaw refers to the JavaScript (node.js) server for Thrift, which is not used or shipped with OpenDaylight or any other part of Red Hat OpenStack Platform.

Metrics

References (15)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jan 7, 2019
Updated Aug 5, 2024
Reserved Jun 5, 2018
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 5, 2018
GHSA-VX85-MJ8C-4QM6