CVE-2017-11610 is a high-severity remote code execution vulnerability affecting the XML-RPC server in Supervisor versions prior to 3.0.1, 3.1.4, 3.2.4, and 3.3.3, including various Debian, Fedora, and Red Hat distributions. This flaw allows remote authenticated attackers to execute arbitrary commands by sending crafted XML-RPC requests, leveraging a weakness in nested supervisord namespace lookups. With a CVSS score of 8.8 (HIGH) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its low attack complexity and complete compromise potential (C:H/I:H/A:H). While not listed on the KEV catalog, public exploit modules exist for Metasploit and Nuclei, and it has garnered substantial community discussion and media coverage, including its association with cryptomining worm activity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.0CPE matchmatch criteria | cpe:2.3:a:supervisord:supervisor:*:*:*:*:*:*:*:* | ||
3.1.0CPE matchmatch criteria | cpe:2.3:a:supervisord:supervisor:3.1.0:*:*:*:*:*:*:* | ||
3.1.1CPE matchmatch criteria | cpe:2.3:a:supervisord:supervisor:3.1.1:*:*:*:*:*:*:* | ||
3.1.2CPE matchmatch criteria | cpe:2.3:a:supervisord:supervisor:3.1.2:*:*:*:*:*:*:* | ||
3.1.3CPE matchmatch criteria | cpe:2.3:a:supervisord:supervisor:3.1.3:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.