The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Thrift | Apache | 0.9.2 (including) | 0.11.0 (including) |
Thrift | Ubuntu | upstream | * |
Red Hat Fuse 7.3.1 | RedHat | camel-thrift | * |
Red Hat Fuse 7.3.1 | RedHat | libthrift | * |
Red Hat JBoss Data Virtualization 6.4.8 | RedHat | libthrift | * |