CVE-2018-7490

Name
CVE-2018-7490
Description
uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
NVD Severity
medium
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
Vendor Advisory https://uwsgi-docs.readthedocs.io/en/latest/Changelog-2.0.17.html
Third Party Advisory https://www.exploit-db.com/exploits/44223/
Third Party Advisory https://www.debian.org/security/2018/dsa-4142

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:unbit:uwsgi:*:*:*:*:*:*:*:* uwsgi >= None < 2.0.17

Vulnerable and fixed packages

Source package Branch Version Maintainer Status