CVE-2019-12105 is a vulnerability in Supervisor through version 4.0.2, allowing an unauthenticated user to read log files or restart services if the inet_http_server component is enabled without a password. This vulnerability carries a CVSS score of 8.2 (HIGH), indicating a network-based attack with low complexity and potential for confidentiality loss and high availability impact. While the affected component is not enabled by default, the maintainer has stated they will not remove the open server functionality, instead adding further warnings to documentation. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.0.2CPE matchmatch criteria | cpe:2.3:a:supervisord:supervisor:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.