The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
📦
thrift
Vendor: apache
Actively Exploited
0
CISA KEV List
PoC / Exploits
0
Code Available
Total RCEs
1
Remote Access
Total CVEs
126
Total Indexed
Avg. EPSS
3.17%
Exploit Prob.
Security Vulnerability Index
Page 4 / 13
6.5
CVSS
Severity: MEDIUM
8.8
CVSS
CVE-2016-5397
RCE
The Apache Thrift Go client library exposed the potential during code generation for command injection due to using an external formatting tool. Affected Apache Thrift 0.9.3 and older, Fixed in Apache Thrift 0.10.0.
Severity: HIGH
6.5
CVSS
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.
Severity: MEDIUM