Missing Authentication for Critical Function in Supervisor - CVE-2019-12105

 

Missing Authentication for Critical Function in Supervisor - CVE-2019-12105

Published: September 10, 2019 / Updated: August 3, 2020


Vulnerability identifier: #VU33160
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-12105
CWE-ID: CWE-306
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to #BASIC_IMPACT#.

** DISPUTED ** In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the ability to run an open server will not be removed but an additional warning was added to the documentation.


Affected software

Supervisor
supervisor (Alpine package)

How to mitigate CVE-2019-12105

Install update from vendor's website.

Supervisor - update to 4.0.3

External References

Related Security Bulletins