The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
2017-08-23T14:29:00.237
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:C/I:C/A:C
8.0
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | supervisord | supervisor | ≤ 3.0 | Yes |
Application | supervisord | supervisor | 3.1.0 | Yes |
Application | supervisord | supervisor | 3.1.1 | Yes |
Application | supervisord | supervisor | 3.1.2 | Yes |
Application | supervisord | supervisor | 3.1.3 | Yes |
Application | supervisord | supervisor | 3.2.0 | Yes |
Application | supervisord | supervisor | 3.2.1 | Yes |
Application | supervisord | supervisor | 3.2.2 | Yes |
Application | supervisord | supervisor | 3.2.3 | Yes |
Application | supervisord | supervisor | 3.3.0 | Yes |
Application | supervisord | supervisor | 3.3.1 | Yes |
Application | supervisord | supervisor | 3.3.2 | Yes |
Operating System | fedoraproject | fedora | 24 | Yes |
Operating System | fedoraproject | fedora | 25 | Yes |
Operating System | fedoraproject | fedora | 26 | Yes |
Operating System | debian | debian_linux | 8.0 | Yes |
Operating System | debian | debian_linux | 9.0 | Yes |
Application | redhat | cloudforms | 4.5 | Yes |