Supervisord Supervisor vulnerabilities
2 known vulnerabilities affecting supervisord/supervisor.
Total CVEs
2
CISA KEV
0
Public exploits
1
Exploited in wild
1
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2019-12105HIGHCVSS 8.2≤ 4.0.22019-09-10
CVE-2019-12105 [HIGH] CWE-306 CVE-2019-12105: In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note:
In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will n
nvdosv
CVE-2017-11610HIGHCVSS 8.8ExploitedPoC≤ 3.0v3.1.0+10 more2017-08-23
CVE-2017-11610 [HIGH] CWE-276 CVE-2017-11610: The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x bef
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
ghsanvdosv