CVE Vulnerabilities

CVE-2018-11798

Insertion of Sensitive Information into Externally-Accessible File or Directory

Published: Jan 07, 2019 | Modified: Nov 07, 2023
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Ubuntu
LOW

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

Weakness

The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.

Affected Software

Name Vendor Start Version End Version
Thrift Apache 0.9.2 (including) 0.11.0 (including)
Thrift Ubuntu upstream *
Red Hat Fuse 7.3.1 RedHat camel-thrift *
Red Hat Fuse 7.3.1 RedHat libthrift *
Red Hat JBoss Data Virtualization 6.4.8 RedHat libthrift *

Potential Mitigations

References