PT-2017-17886 · Apache · Apache Mesos

Publicado

2017-09-28

·

Atualizado

2022-05-13

·

CVE-2017-7687

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Mesos versions prior to 1.1.3 Apache Mesos versions 1.2.x prior to 1.2.2 Apache Mesos versions 1.3.x prior to 1.3.1 Apache Mesos version 1.4.0-dev
Description The issue arises when handling a decoding failure for a malformed URL path of an HTTP request. This can cause libprocess in Apache Mesos to crash due to the code accidentally calling an inappropriate function. As a result, a malicious actor can cause a denial of service of Mesos masters, rendering the Mesos-controlled cluster inoperable.
Recommendations For Apache Mesos versions prior to 1.1.3, update to version 1.1.3 or later. For Apache Mesos versions 1.2.x prior to 1.2.2, update to version 1.2.2 or later. For Apache Mesos versions 1.3.x prior to 1.3.1, update to version 1.3.1 or later. For Apache Mesos version 1.4.0-dev, update to a stable version that includes the fix.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-7687
GHSA-X869-784M-JMJ2

Produtos afetados

Apache Mesos