Bug 1667188 (CVE-2018-11798)
Summary: | CVE-2018-11798 thrift: Improper Access Control grants access to files outside the webservers docroot path | ||
---|---|---|---|
Product: | [Other] Security Response | Reporter: | Laura Pardo <lpardo> |
Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
Status: | CLOSED ERRATA | QA Contact: | |
Severity: | high | Docs Contact: | |
Priority: | high | ||
Version: | unspecified | CC: | ahardin, bleanhar, bmontgom, ccoleman, dbecker, dedgar, eparis, jburrell, jgoulding, jjoyce, jochrist, jokerman, jschluet, kbasil, lhh, lpeer, mburns, mchappel, nstielau, sclewis, slinaber, sponnaga |
Target Milestone: | --- | Keywords: | Security |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | thrift 0.12.0 | Doc Type: | If docs needed, set a value |
Doc Text: |
A flaw was found in the Node.js static web server in Apache Thrift, where it allowed a remote user to access files outside of the set web servers' docroot path. An attacker could use this flaw to possibly access unauthorized files and sensitive information.
|
Story Points: | --- |
Clone Of: | Environment: | ||
Last Closed: | 2019-07-12 13:06:28 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | 1667189, 1667190, 1700972, 1700973, 1700982, 1700983 | ||
Bug Blocks: | 1667192 |
Description
Laura Pardo
2019-01-17 16:57:24 UTC
Created thrift tracking bugs for this issue: Affects: epel-7 [bug 1667189] Affects: fedora-all [bug 1667190] Statement: OpenStack and OpenDaylight: The Java implementation of thrift is used in OpenDaylight by parts of the vpnservice functionality. This flaw refers to the JavaScript (node.js) server for Thrift, which is not used or shipped with OpenDaylight or any other part of Red Hat OpenStack Platform. This vulnerability is out of security support scope for the following product: * Red Hat JBoss Fuse Service Works 6 Please refer to https://access.redhat.com/support/policy/updates/jboss_notes for more details. JBoss Operations Network does not use the the vulnerable component marking as wontfix. This issue has been addressed in the following products: Red Hat Fuse 7.3.1 Via RHSA-2019:1545 https://access.redhat.com/errata/RHSA-2019:1545 This bug is now closed. Further updates for individual products will be reflected on the CVE page(s): https://access.redhat.com/security/cve/cve-2018-11798 This issue has been addressed in the following products: Red Hat JBoss Data Virtualization 6.4.8 Via RHSA-2019:3140 https://access.redhat.com/errata/RHSA-2019:3140 |