CVE-2019-15149 describes a critical vulnerability in Mitogen versions prior to 0.2.8, specifically within the core.py component, affecting the networkgenomics Mitogen library. A typo inadvertently disables a crucial unidirectional-routing protection mechanism when a child process is initiated by another child. This vulnerability carries a CVSS score of 9.8 (Critical), indicating a high potential for complete compromise of confidentiality, integrity, and availability, with no user interaction or authentication required. Despite the high severity, the vendor disputes its exploitability without additional hypothetical factors. Currently, there is no evidence of active exploitation, nor are there any public exploit codes available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are also absent, suggesting a low level of public awareness or attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.2.8CPE matchmatch criteria | cpe:2.3:a:networkgenomics:mitogen:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.