Junglewise Threat Intelligence

CVE-2017-11610: PYSEC-2017-41 - The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated us

CVE-2017-11610 · Severity: low · CVSS 3 · Published 2017-08-23

Technologies: supervisor (PyPI). Vendors: PyPI.

Executive brief

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

Affected products

  • PyPI supervisor

Related threats