The Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in which a remote user has the ability to access files outside the set webservers docroot path.
{ "versions": [ { "introduced": "0.9.2" }, { "last_affected": "0.11.0" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-11798.json"