{
  "threat_severity" : "Important",
  "public_date" : "2018-10-05T00:00:00Z",
  "bugzilla" : {
    "description" : "thrift: Improper Access Control grants access to files outside the  webservers docroot path",
    "id" : "1667188",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=1667188"
  },
  "cvss3" : {
    "cvss3_base_score" : "7.5",
    "cvss3_scoring_vector" : "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-284->CWE-22",
  "details" : [ "The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.", "A flaw was found in the Node.js static web server in Apache Thrift, where it allowed a remote user to access files outside of the set web servers' docroot path. An attacker could use this flaw to possibly access unauthorized files and sensitive information." ],
  "statement" : "OpenStack and OpenDaylight:\nThe Java implementation of thrift is used in OpenDaylight by parts of the vpnservice functionality. This flaw refers to the JavaScript (node.js) server for Thrift, which is not used or shipped with OpenDaylight or any other part of Red Hat OpenStack Platform.",
  "affected_release" : [ {
    "product_name" : "Red Hat Fuse 7.3.1",
    "release_date" : "2019-06-18T00:00:00Z",
    "advisory" : "RHSA-2019:1545",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "camel-thrift"
  }, {
    "product_name" : "Red Hat Fuse 7.3.1",
    "release_date" : "2019-06-18T00:00:00Z",
    "advisory" : "RHSA-2019:1545",
    "cpe" : "cpe:/a:redhat:jboss_fuse:7",
    "package" : "libthrift"
  }, {
    "product_name" : "Red Hat JBoss Data Virtualization 6.4.8",
    "release_date" : "2019-10-17T00:00:00Z",
    "advisory" : "RHSA-2019:3140",
    "cpe" : "cpe:/a:redhat:jboss_data_virtualization:6.4",
    "package" : "libthrift"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat JBoss Fuse Service Works 6",
    "fix_state" : "Out of support scope",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:jboss_fuse_service_works:6"
  }, {
    "product_name" : "Red Hat JBoss Operations Network 3",
    "fix_state" : "Will not fix",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:jboss_operations_network:3"
  }, {
    "product_name" : "Red Hat OpenShift Application Runtimes",
    "fix_state" : "Affected",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:openshift_application_runtimes:1.0"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.10",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.10"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.11",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.11"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.4",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.4"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.5",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.5"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.6",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.6"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.7",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.7"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 3.9",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:3.9"
  }, {
    "product_name" : "Red Hat OpenShift Container Platform 4",
    "fix_state" : "Not affected",
    "package_name" : "thrift",
    "cpe" : "cpe:/a:redhat:openshift:4"
  }, {
    "product_name" : "Red Hat OpenStack Platform 10 (Newton)",
    "fix_state" : "Not affected",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:openstack:10"
  }, {
    "product_name" : "Red Hat OpenStack Platform 13 (Queens)",
    "fix_state" : "Not affected",
    "package_name" : "opendaylight",
    "cpe" : "cpe:/a:redhat:openstack:13"
  }, {
    "product_name" : "Red Hat OpenStack Platform 14 (Rocky)",
    "fix_state" : "Not affected",
    "package_name" : "libthrift",
    "cpe" : "cpe:/a:redhat:openstack:14"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2018-11798\nhttps://nvd.nist.gov/vuln/detail/CVE-2018-11798" ],
  "name" : "CVE-2018-11798",
  "csaw" : false
}