CyberSec.Space Logo
CVEブラウザに戻る

CVE-2017-11610

HIGH
8.8
CVSS Severity Score
EPSS Score0.1390%
EPSS Percentile36.93th
Published2017年8月23日
Last Modified2026年5月13日

Vulnerability Description

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

Affected Platforms (CPE)

📦
Supervisord

Supervisor

<= 3.0
📦
Supervisord

Supervisor

= 3.1.0
📦
Supervisord

Supervisor

= 3.1.1
📦
Supervisord

Supervisor

= 3.1.2
📦
Supervisord

Supervisor

= 3.1.3
📦
Supervisord

Supervisor

= 3.2.0
📦
Supervisord

Supervisor

= 3.2.1
📦
Supervisord

Supervisor

= 3.2.2
📦
Supervisord

Supervisor

= 3.2.3
📦
Supervisord

Supervisor

= 3.3.0
📦
Supervisord

Supervisor

= 3.3.1
📦
Supervisord

Supervisor

= 3.3.2
💻
Fedoraproject

Fedora

= 24
💻
Fedoraproject

Fedora

= 25
💻
Fedoraproject

Fedora

= 26
💻
Debian

Debian Linux

= 8.0
💻
Debian

Debian Linux

= 9.0
📦
Redhat

Cloudforms

= 4.5

References & Advisories

関連する脆弱性情報