CVE-2018-11798
ADVISORY - githubSummary
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
EPSS Score: 0.00402 (0.608)
Common Weakness Enumeration (CWE)
ADVISORY - nist
Insertion of Sensitive Information into Externally-Accessible File or Directory
ADVISORY - github
Insertion of Sensitive Information into Externally-Accessible File or Directory
ADVISORY - gitlab
Sign in to Docker Scout
See which of your images are affected by this CVE and how to fix them by signing into Docker Scout.
Sign in