{"id":"CVE-2017-11610","aliases":["GHSA-x7c8-4x3h-874w","PYSEC-2017-41"],"url":"https://o3.security/vulnerability/CVE-2017-11610","summary":"Incorrect Default Permissions in Supervisor","details":"The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.","published":"2017-08-23T14:29:00.237Z","modified":"2026-07-08T05:51:22.440537338Z","cvss":{"score":8.8,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":8,"affectedPackages":[{"ecosystem":"PyPI","name":"supervisor","fixedVersion":"3.0.1"},{"ecosystem":"PyPI","name":"supervisor","fixedVersion":"3.1.4"},{"ecosystem":"PyPI","name":"supervisor","fixedVersion":"3.2.4"},{"ecosystem":"PyPI","name":"supervisor","fixedVersion":"3.3.3"}],"fix":null,"references":[{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/4GMSCGMM477N64Z3BM34RWYBGSLK466B/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DTPDZV4ZRICDYAYZVUHSYZAYDLRMG2IM/"},{"type":"WEB","url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JXGWOJNSWWK2TTWQJZJUP66FLFIWDMBQ/"},{"type":"ADVISORY","url":"http://www.debian.org/security/2017/dsa-3942"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2017:3005"},{"type":"ADVISORY","url":"https://github.com/Supervisor/supervisor/blob/3.0.1/CHANGES.txt"},{"type":"ADVISORY","url":"https://github.com/Supervisor/supervisor/blob/3.1.4/CHANGES.txt"},{"type":"ADVISORY","url":"https://github.com/Supervisor/supervisor/blob/3.2.4/CHANGES.txt"},{"type":"ADVISORY","url":"https://github.com/Supervisor/supervisor/blob/3.3.3/CHANGES.txt"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/201709-06"},{"type":"REPORT","url":"https://github.com/Supervisor/supervisor/issues/964"},{"type":"EVIDENCE","url":"https://www.exploit-db.com/exploits/42779/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T05:51:22.440537338Z"}}