Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2017-11610

Опубликовано: 23 авг. 2017
Источник: ubuntu
Приоритет: medium
CVSS2: 9
CVSS3: 8.8

Описание

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

РелизСтатусПримечание
artful

not-affected

3.3.1-1.1
bionic

not-affected

3.3.1-1.1
devel

not-affected

3.3.1-1.1
esm-apps/bionic

not-affected

3.3.1-1.1
esm-apps/xenial

released

3.2.0-2ubuntu0.2
esm-infra-legacy/trusty

released

3.0b2-1ubuntu0.1
precise/esm

DNE

trusty

released

3.0b2-1ubuntu0.1
trusty/esm

released

3.0b2-1ubuntu0.1
upstream

released

3.3.1-1.1

Показывать по

9 Critical

CVSS2

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7
redhat
больше 8 лет назад

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

CVSS3: 8.8
nvd
больше 8 лет назад

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

CVSS3: 8.8
debian
больше 8 лет назад

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2 ...

CVSS3: 8.8
github
больше 3 лет назад

Incorrect Default Permissions in Supervisor

fstec
больше 8 лет назад

Уязвимость компонента XML-RPC веб-сервера Supervisor и операционных систем Fedora, Debian GNU/Linux , позволяющая нарушителю выполнить произвольные команды

9 Critical

CVSS2

8.8 High

CVSS3