Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2019-12105

Опубликовано: 10 сент. 2019
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 6.4
CVSS3: 8.2

Описание

In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation

РелизСтатусПримечание
bionic

ignored

end of standard support, was needs-triage
devel

not-affected

disputed
esm-apps/bionic

not-affected

disputed
esm-apps/focal

not-affected

disputed
esm-apps/jammy

not-affected

disputed
esm-apps/noble

not-affected

disputed
esm-apps/xenial

not-affected

disputed
esm-infra-legacy/trusty

not-affected

disputed
focal

not-affected

disputed
groovy

ignored

end of life

Показывать по

EPSS

Процентиль: 82%
0.01812
Низкий

6.4 Medium

CVSS2

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
больше 6 лет назад

In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation

CVSS3: 8.2
debian
больше 6 лет назад

In Supervisor through 4.0.2, an unauthenticated user can read log file ...

github
больше 3 лет назад

In supervisord in Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. WARNING: This issue will not be fixed by the maintainer. The ability to run an open server will not be removed because users often use it for local development, therefore no action will be taken.

CVSS3: 8.2
fstec
больше 6 лет назад

Уязвимость компонента inet_http_server системы контроля процессов Supervisor, позволяющая нарушителю получить доступ к конфиденциальным данным, а также вызвать отказ в обслуживании

EPSS

Процентиль: 82%
0.01812
Низкий

6.4 Medium

CVSS2

8.2 High

CVSS3