Exposure of Private Personal Information to an Unauthorized Actor Affecting supervisor package, versions [,4.0.4)
Threat Intelligence
EPSS
0.36% (73rd
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-SUPERVISOR-6745395
- published 1 May 2024
- disclosed 1 May 2024
- credit Luan Souza
Introduced: 1 May 2024
CVE-2019-12105 Open this link in a new tabHow to fix?
Upgrade supervisor
to version 4.0.4 or higher.
Overview
Affected versions of this package are vulnerable to Exposure of Private Personal Information to an Unauthorized Actor when the inet_http_server
component is enabled without a password. This allows an unauthenticated user to read log files or restart a service.
References
CVSS Scores
version 3.1