{"id":"GHSA-x7c8-4x3h-874w","summary":"Incorrect Default Permissions in Supervisor","details":"The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.","aliases":["CVE-2017-11610","PYSEC-2017-41"],"modified":"2024-10-28T15:07:56.792734Z","published":"2022-05-13T01:42:26Z","database_specific":{"nvd_published_at":"2017-08-23T14:29:00Z","cwe_ids":["CWE-276"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-07-01T21:43:13Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2017-11610"},{"type":"WEB","url":"https://github.com/Supervisor/supervisor/issues/964"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2017:3005"},{"type":"WEB","url":"https://github.com/Supervisor/supervisor"},{"type":"WEB","url":"https://github.com/Supervisor/supervisor/blob/3.0.1/CHANGES.txt"},{"type":"WEB","url":"https://github.com/Supervisor/supervisor/blob/3.1.4/CHANGES.txt"},{"type":"WEB","url":"https://github.com/Supervisor/supervisor/blob/3.2.4/CHANGES.txt"},{"type":"WEB","url":"https://github.com/Supervisor/supervisor/blob/3.3.3/CHANGES.txt"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-x7c8-4x3h-874w"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/supervisor/PYSEC-2017-41.yaml"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4GMSCGMM477N64Z3BM34RWYBGSLK466B"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DTPDZV4ZRICDYAYZVUHSYZAYDLRMG2IM"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JXGWOJNSWWK2TTWQJZJUP66FLFIWDMBQ"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201709-06"},{"type":"WEB","url":"https://www.exploit-db.com/exploits/42779"},{"type":"WEB","url":"http://www.debian.org/security/2017/dsa-3942"}],"affected":[{"package":{"name":"supervisor","ecosystem":"PyPI","purl":"pkg:pypi/supervisor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.0.1"}]}],"versions":["2.0","2.0b1","2.1","2.1b1","2.2b1","3.0","3.0a1","3.0a10","3.0a11","3.0a12","3.0a2","3.0a3","3.0a4","3.0a5","3.0a6","3.0a7","3.0a8","3.0a9","3.0b1","3.0b2","a3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x7c8-4x3h-874w/GHSA-x7c8-4x3h-874w.json"}},{"package":{"name":"supervisor","ecosystem":"PyPI","purl":"pkg:pypi/supervisor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.1.0"},{"fixed":"3.1.4"}]}],"versions":["3.1.0","3.1.1","3.1.2","3.1.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x7c8-4x3h-874w/GHSA-x7c8-4x3h-874w.json"}},{"package":{"name":"supervisor","ecosystem":"PyPI","purl":"pkg:pypi/supervisor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.2.0"},{"fixed":"3.2.4"}]}],"versions":["3.2.0","3.2.1","3.2.2","3.2.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x7c8-4x3h-874w/GHSA-x7c8-4x3h-874w.json"}},{"package":{"name":"supervisor","ecosystem":"PyPI","purl":"pkg:pypi/supervisor"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.3.0"},{"fixed":"3.3.3"}]}],"versions":["3.3.0","3.3.1","3.3.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-x7c8-4x3h-874w/GHSA-x7c8-4x3h-874w.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}