Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-12105

Опубликовано: 10 сент. 2019
Источник: debian

Описание

In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation

Пакеты

ПакетСтатусВерсия исправленияРелизТип
supervisorunfixedpackage

Примечания

  • https://github.com/Supervisor/supervisor/issues/1245

  • Disupted upstream to be vulnerability. inet_http_server is not enabled by

  • default (neither upstream nor in Debian packaging). Details in the upstream

  • issue.

Связанные уязвимости

CVSS3: 8.2
ubuntu
больше 6 лет назад

In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation

CVSS3: 8.2
nvd
больше 6 лет назад

In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation

github
больше 3 лет назад

In supervisord in Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. WARNING: This issue will not be fixed by the maintainer. The ability to run an open server will not be removed because users often use it for local development, therefore no action will be taken.

CVSS3: 8.2
fstec
больше 6 лет назад

Уязвимость компонента inet_http_server системы контроля процессов Supervisor, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании