In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T23:10:30.578Z
Reserved: 2019-05-15T00:00:00
Link: CVE-2019-12105
Updated: 2024-08-04T23:10:30.578Z
Status : Modified
Published: 2019-09-10T17:15:11.517
Modified: 2024-11-21T04:22:12.587
Link: CVE-2019-12105
No data.
OpenCVE Enrichment
No data.
Weaknesses