{"id":"GHSA-vx85-mj8c-4qm6","summary":"Apache Thrift Node.js static web server sandbox escape","details":"The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.","aliases":["CVE-2018-11798"],"modified":"2026-07-17T21:06:14.390661790Z","published":"2019-01-17T13:56:33Z","database_specific":{"github_reviewed_at":"2020-06-16T21:58:46Z","nvd_published_at":null,"cwe_ids":["CWE-538"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-11798"},{"type":"WEB","url":"https://github.com/apache/thrift/pull/1606"},{"type":"WEB","url":"https://github.com/apache/thrift/commit/2a2b72f6c8aef200ecee4984f011e06052288ff2"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1545"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:3140"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-vx85-mj8c-4qm6"},{"type":"WEB","url":"https://issues.apache.org/jira/browse/THRIFT-4647"},{"type":"WEB","url":"https://lists.apache.org/thread.html/6e9edd282684896cedf615fb67a02bebfe6007f2d5baf03ba52e34fd@%3Cuser.thrift.apache.org%3E"},{"type":"WEB","url":"https://web.archive.org/web/20200227094236/http://www.securityfocus.com/bid/106501"},{"type":"WEB","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"}],"affected":[{"package":{"name":"org.apache.thrift:libthrift","ecosystem":"Maven","purl":"pkg:maven/org.apache.thrift/libthrift"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0.9.2"},{"fixed":"0.12.0"}]}],"versions":["0.10.0","0.11.0","0.9.2","0.9.3","0.9.3-1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/01/GHSA-vx85-mj8c-4qm6/GHSA-vx85-mj8c-4qm6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}