cbcvebase.
CVE-2017-11610
published 2017-08-23

CVE-2017-11610: The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute…

high8.8CVSS 3.0
AVNACLPRLUINSUCHIHAH
ITWEXPLOIT
Exploited in the wild
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

Affected

27 ranges· showing 25
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiansupervisor< supervisor 3.3.1-1.1 (bookworm)supervisor 3.3.1-1.1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
redhatcloudforms
supervisordsupervisor<= 3.0
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor
supervisordsupervisor>= 0 < 3.3.1-1.13.3.1-1.1
supervisordsupervisor>= 0 < 3.3.1-1.13.3.1-1.1
supervisordsupervisor>= 0 < 3.3.1-1.13.3.1-1.1
supervisordsupervisor>= 0 < 3.3.1-1.13.3.1-1.1
supervisordsupervisor>= 0 < 3.0.13.0.1
supervisordsupervisor>= 3.1.0 < 3.1.43.1.4

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
vulncheck8.8HIGH