{"id":"CVE-2018-11798","aliases":["GHSA-vx85-mj8c-4qm6"],"url":"https://o3.security/vulnerability/CVE-2018-11798","summary":"Apache Thrift Node.js static web server sandbox escape","details":"The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.","published":"2019-01-07T17:29:00.283Z","modified":"2026-07-08T14:14:07.575563Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},"epss":{"score":0.05325,"percentile":0.92047,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Maven","name":"org.apache.thrift:libthrift","fixedVersion":"0.12.0"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.apache.org/thread.html/6e9edd282684896cedf615fb67a02bebfe6007f2d5baf03ba52e34fd%40%3Cuser.thrift.apache.org%3E"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/106501"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:1545"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2019:3140"},{"type":"ADVISORY","url":"https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T14:14:07.575563Z"}}