QID 982324
QID 982324: Java (maven) Security Update for org.apache.thrift:libthrift (GHSA-vx85-mj8c-4qm6)
The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-vx85-mj8c-4qm6 for updates pertaining to this vulnerability.
Vendor References
- GHSA-vx85-mj8c-4qm6 -
github.com/advisories/GHSA-vx85-mj8c-4qm6
CVEs related to QID 982324
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vx85-mj8c-4qm6 | org.apache.thrift:libthrift |
|