CVE-2017-11610
23.08.2017, 14:29
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.Enginsight
Vendor | Product | Version |
---|---|---|
supervisord | supervisor | 𝑥 ≤ 3.0 |
supervisord | supervisor | 3.1.0 |
supervisord | supervisor | 3.1.1 |
supervisord | supervisor | 3.1.2 |
supervisord | supervisor | 3.1.3 |
supervisord | supervisor | 3.2.0 |
supervisord | supervisor | 3.2.1 |
supervisord | supervisor | 3.2.2 |
supervisord | supervisor | 3.2.3 |
supervisord | supervisor | 3.3.0 |
supervisord | supervisor | 3.3.1 |
supervisord | supervisor | 3.3.2 |
debian | debian_linux | 8.0 |
debian | debian_linux | 9.0 |
redhat | cloudforms | 4.5 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration
References