Loading
An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.
Use CWE-22, Lighttpd vendor hub and Lighttpd product page to widen CVE-2018-19052 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-11072, CVE-2014-2323 and CVE-2013-4559 for nearby disclosures in the same product family.