CVE-2018-19052
Severity CVSS v4.0:
Pending analysis
Type:
CWE-22
Path Traversal
Publication date:
07/11/2018
Last modified:
31/03/2022
Description
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:lighttpd:lighttpd:*:*:*:*:*:*:*:* | 1.4.50 (excluding) | |
| cpe:2.3:a:opensuse:backports_sle:15.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp4:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:12:*:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp1:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp2:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp3:*:*:*:*:*:* | ||
| cpe:2.3:o:suse:suse_linux_enterprise_server:12:sp4:*:*:*:*:*:* | ||
| cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



