Exhibitor Project maintains a niche Apache Curator-based distributed system for service discovery and configuration management, represented by its Exhibitor product. The observed vulnerability profile centers on OS command injection, a critical risk in command-execution contexts that reflects the tool's administrative and orchestration role. Current severity, exploitation activity, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Exhibitor Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-5029CRITICAL An exploitable command injection vulnerability exists in the Config editor of the Exhibitor Web UI versions 1.0.9 to 1.7.1. Arbitrary shell commands surrounded by backticks or $() | Nov 13, 2019 | 9.8 | 72 | NO | YES |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Exhibitor Project.
Media articles that mention a CVE ID that affects a product developed by Exhibitor Project — matched by CVE ID, not by vendor name.