Supervisord is a widely deployed process-control and monitoring system for Unix environments, used extensively to manage long-running services and application daemons across development, testing, and production infrastructure. Its vulnerability surface centers on the supervisor product and recurs through access-control weaknesses including incorrect default permissions and missing authentication for critical functions, reflecting the administrative exposure inherent to a daemon-management tool that often runs with elevated privilege. Current exploitation activity, severity levels, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Supervisord over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-11610HIGH The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a | Aug 23, 2017 | 8.8 | 91 | NO | YES |
CVE-2019-12105HIGH In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not e | Sep 10, 2019 | 8.2 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Supervisord.
Media articles that mention a CVE ID that affects a product developed by Supervisord — matched by CVE ID, not by vendor name.