Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2018-11798

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.006
EPSS Ranking 69.5%
CVSS Severity
CVSS v3 Score 6.5
CVSS v2 Score 4.0
Products affected by CVE-2018-11798
  • Apache » Thrift » Version: 0.10.0
    cpe:2.3:a:apache:thrift:0.10.0
  • Apache » Thrift » Version: 0.11.0
    cpe:2.3:a:apache:thrift:0.11.0
  • Apache » Thrift » Version: 0.9.2
    cpe:2.3:a:apache:thrift:0.9.2
  • Apache » Thrift » Version: 0.9.3
    cpe:2.3:a:apache:thrift:0.9.3


Contact Us

Shodan ® - All rights reserved