uWSGI before 2.0.17 mishandles a DOCUMENT_ROOT check during use of the --php-docroot option, allowing directory traversal.
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-7490.json"
[
{
"source": "https://github.com/unbit/uwsgi/commit/50ffc6b28a7a84e273fb2b79c8d657b45887fe87",
"digest": {
"length": 4401.0,
"function_hash": "40819405896703077170114517224641591161"
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Function",
"target": {
"file": "core/emperor.c",
"function": "emperor_send_stats"
},
"id": "CVE-2018-7490-10a9e9fb"
},
{
"source": "https://github.com/unbit/uwsgi/commit/50ffc6b28a7a84e273fb2b79c8d657b45887fe87",
"digest": {
"line_hashes": [
"183921310509659873877742638882587627729",
"253732705211709347952798536006006680026",
"70117204752041438384735343179857933391",
"250711984050732733881674518222307053012",
"156477072178116142811456001594875906112",
"110936179626844845554820386236306811073",
"175571910637939687637911481670568491034"
],
"threshold": 0.9
},
"signature_version": "v1",
"deprecated": false,
"signature_type": "Line",
"target": {
"file": "core/emperor.c"
},
"id": "CVE-2018-7490-dad61214"
}
]