Your RSA-2048 keys break in 2030. Find every one of them before attackers do.
🐍 PyPI

GHSA-x7c8-4x3h-874w

HIGH

Incorrect Default Permissions in Supervisor

Also known asCVE-2017-11610PYSEC-2017-41
Published
May 13, 2022
Updated
Oct 28, 2024
Affected
4 pkgs
Patched
4 / 4
Exploits
8 known

EPSS Exploitation Probability

via FIRST.org ↗
94.2%probability of exploitation in next 30 days
Very High Risk100th percentile+0.41%
93.3%93.8%94.3%94.7%93.8%94.2%Dec 25Apr 26Jun 26

EPSS (Exploit Prediction Scoring System) is a daily probability model maintained by FIRST.org. It estimates the likelihood a CVE will be exploited in production environments within the next 30 days, derived from real-world threat intelligence signals.

Blast Radius

4 pkgs affected
🐍supervisor🐍supervisor🐍supervisor🐍supervisor

Real-time download stats are indexed for npm and PyPI packages. This vulnerability affects PyPI packages — download data is not available via public APIs for these ecosystems.

Description

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.

Affected Packages

4 total 4 fixed
EcosystemPackageVulnerable rangeFix
🐍PyPIsupervisorall versions3.0.1
🐍PyPIsupervisor3.1.0&&< 3.1.43.1.4
🐍PyPIsupervisor3.2.0&&< 3.2.43.2.4
🐍PyPIsupervisor3.3.0&&< 3.3.33.3.3
Exploits & PoCs
8

Research use only. For defensive security, authorized penetration testing, and academic research only. Never execute exploit code against systems without explicit written authorization.

EDB-42779remotelinux✓ Verified

Supervisor 3.0a1 < 3.3.2 - XML-RPC (Authenticated) Remote Code Execution (Metasploit)

by Metasploit · Sep 25, 2017

Frequently Asked Questions

The XML-RPC server in supervisor before 3.0.1, 3.1.x before 3.1.4, 3.2.x before 3.2.4, and 3.3.x before 3.3.3 allows remote authenticated users to execute arbitrary commands via a crafted XML-RPC request, related to nested supervisord namespace lookups.
O3 Security · Impact-Aware SCA

Is GHSA-x7c8-4x3h-874w in your stack?

O3 detects GHSA-x7c8-4x3h-874w across PyPI dependencies and uses function-level reachability to confirm whether the vulnerable code path is actually reachable — not just present. No false positives.