Описание
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
A vulnerability was found in the XML-RPC interface in supervisord. When processing malformed commands, an attacker can cause arbitrary shell commands to be executed on the server as the same user as supervisord. Exploitation requires the attacker to first be authenticated to the supervisord service.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Ceph Storage 1.3 | supervisor | Will not fix | ||
| Red Hat Ceph Storage 2 | supervisor | Will not fix | ||
| Red Hat Mobile Application Platform 4 | nagios | Not affected | ||
| CloudForms Management Engine 5.8 | ansible-tower | Fixed | RHSA-2017:3005 | 24.10.2017 |
| CloudForms Management Engine 5.8 | cfme | Fixed | RHSA-2017:3005 | 24.10.2017 |
| CloudForms Management Engine 5.8 | cfme-appliance | Fixed | RHSA-2017:3005 | 24.10.2017 |
| CloudForms Management Engine 5.8 | cfme-gemset | Fixed | RHSA-2017:3005 | 24.10.2017 |
| CloudForms Management Engine 5.8 | rabbitmq-server | Fixed | RHSA-2017:3005 | 24.10.2017 |
| CloudForms Management Engine 5.8 | rh-ruby23-rubygem-nokogiri | Fixed | RHSA-2017:3005 | 24.10.2017 |
| CloudForms Management Engine 5.8 | supervisor | Fixed | RHSA-2017:3005 | 24.10.2017 |
Показывать по
Дополнительная информация
Статус:
EPSS
7 High
CVSS3
Связанные уязвимости
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2 ...
Уязвимость компонента XML-RPC веб-сервера Supervisor и операционных систем Fedora, Debian GNU/Linux , позволяющая нарушителю выполнить произвольные команды
EPSS
7 High
CVSS3