CyberSec.Space Logo
Back to CVE Browser

CVE-2017-11610

HIGH
8.8
CVSS Severity Score
EPSS Score0.1390%
EPSS Percentile36.93th
PublishedAug 23, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

Affected Platforms (CPE)

πŸ“¦
Supervisord

Supervisor

<= 3.0
πŸ“¦
Supervisord

Supervisor

= 3.1.0
πŸ“¦
Supervisord

Supervisor

= 3.1.1
πŸ“¦
Supervisord

Supervisor

= 3.1.2
πŸ“¦
Supervisord

Supervisor

= 3.1.3
πŸ“¦
Supervisord

Supervisor

= 3.2.0
πŸ“¦
Supervisord

Supervisor

= 3.2.1
πŸ“¦
Supervisord

Supervisor

= 3.2.2
πŸ“¦
Supervisord

Supervisor

= 3.2.3
πŸ“¦
Supervisord

Supervisor

= 3.3.0
πŸ“¦
Supervisord

Supervisor

= 3.3.1
πŸ“¦
Supervisord

Supervisor

= 3.3.2
πŸ’»
Fedoraproject

Fedora

= 24
πŸ’»
Fedoraproject

Fedora

= 25
πŸ’»
Fedoraproject

Fedora

= 26
πŸ’»
Debian

Debian Linux

= 8.0
πŸ’»
Debian

Debian Linux

= 9.0
πŸ“¦
Redhat

Cloudforms

= 4.5

References & Advisories

Related Vulnerabilities