VDB
Sign up
MEDIUM6.5

GHSA-vx85-mj8c-4qm6

Apache Thrift Node.js static web server sandbox escape

Quick fix

GHSA-vx85-mj8c-4qm6 — org.apache.thrift:libthrift: upgrade to the fixed version with the command below.

# pom.xml: bump <version>0.12.0</version> for org.apache.thrift:libthrift

Details

The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.

Are you affected?

Enter the version of the package you're using.

Affected packages

Maven/org.apache.thrift:libthrift
Introduced in: 0.9.2Fixed in: 0.12.0
Fix# pom.xml: bump <version>0.12.0</version> for org.apache.thrift:libthrift

References