CVE-2019-12105
published 2019-09-10CVE-2019-12105: In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component…
PriorityP343high8.2CVSS 3.1
AVNACLPRNUINSUCLINAH
EPSS
2.28%
81.2th percentile
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | supervisor | — | — |
| supervisord | supervisor | <= 4.0.2 | — |
| supervisord | supervisor | >= 0 < 4e334d9cf2a1daff685893e35e72398437df3dcb | 4e334d9cf2a1daff685893e35e72398437df3dcb |
| supervisord | supervisor | >= 0 < 4.0.3 | 4.0.3 |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvdv2.06.4MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:P
osv8.2HIGH
vendor_debian8.2LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2019-12105: supervisor - In Supervisor through 4.0.2, an unauthenticated user can read log files or resta...
vendor_debian·2019·CVSS 8.2
CVE-2019-12105 [HIGH] CVE-2019-12105: supervisor - In Supervisor through 4.0.2, an unauthenticated user can read log files or resta...
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation
Scope: local
bookworm: open
bullseye: open
forky: open
sid: open
trixie: open
GHSA
GHSA-6x94-2xr2-xgw3: In supervisord in Supervisor through 4
ghsa_unreviewed·2022-05-24
CVE-2019-12105 [MEDIUM] GHSA-6x94-2xr2-xgw3: In supervisord in Supervisor through 4
In supervisord in Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. WARNING: This issue will not be fixed by the maintainer. The ability to run an open server will not be removed because users often use it for local development, therefore no action will be taken.
OSV
CVE-2019-12105: ** DISPUTED ** In Supervisor through 4
osv·2019-09-10
CVE-2019-12105 CVE-2019-12105: ** DISPUTED ** In Supervisor through 4
** DISPUTED ** In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation.
OSV
CVE-2019-12105: In Supervisor through 4
osv·2019-09-10·CVSS 8.2
CVE-2019-12105 [HIGH] CVE-2019-12105: In Supervisor through 4
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://supervisord.org/configuration.html#inet-http-server-section-settingshttps://github.com/Supervisor/supervisor/commit/4e334d9cf2a1daff685893e35e72398437df3dcbhttps://github.com/Supervisor/supervisor/issues/1245http://supervisord.org/configuration.html#inet-http-server-section-settingshttps://github.com/Supervisor/supervisor/commit/4e334d9cf2a1daff685893e35e72398437df3dcbhttps://github.com/Supervisor/supervisor/issues/1245
2019-09-10
Published