9

CVE-2017-11610

Exploit

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SupervisordSupervisor Version <= 3.0
SupervisordSupervisor Version3.1.0
SupervisordSupervisor Version3.1.1
SupervisordSupervisor Version3.1.2
SupervisordSupervisor Version3.1.3
SupervisordSupervisor Version3.2.0
SupervisordSupervisor Version3.2.1
SupervisordSupervisor Version3.2.2
SupervisordSupervisor Version3.2.3
SupervisordSupervisor Version3.3.0
SupervisordSupervisor Version3.3.1
SupervisordSupervisor Version3.3.2
FedoraprojectFedora Version24
FedoraprojectFedora Version25
FedoraprojectFedora Version26
DebianDebian Linux Version8.0
DebianDebian Linux Version9.0
RedhatCloudforms Version4.5
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 93.79% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-276 Incorrect Default Permissions

During installation, installed file permissions are set to allow anyone to modify those files.