Vulnerability Description
When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Heron | >= 0.13.0, <= 0.17.8 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/107430Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/5ea1a102d87a47c5912d745fa0d5dfa2830fc94099c
- http://www.securityfocus.com/bid/107430Third Party AdvisoryVDB Entry
- https://lists.apache.org/thread.html/5ea1a102d87a47c5912d745fa0d5dfa2830fc94099c
FAQ
What is CVE-2018-11789?
CVE-2018-11789 is a vulnerability with a CVSS score of 7.5 (HIGH). When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the direc...
How severe is CVE-2018-11789?
CVE-2018-11789 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-11789?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Heron.