PT-2017-17886 · Apache · Apache Mesos
Published
2017-09-28
·
Updated
2022-05-13
·
CVE-2017-7687
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Mesos versions prior to 1.1.3
Apache Mesos versions 1.2.x prior to 1.2.2
Apache Mesos versions 1.3.x prior to 1.3.1
Apache Mesos version 1.4.0-dev
Description
The issue arises when handling a decoding failure for a malformed URL path of an HTTP request. This can cause libprocess in Apache Mesos to crash due to the code accidentally calling an inappropriate function. As a result, a malicious actor can cause a denial of service of Mesos masters, rendering the Mesos-controlled cluster inoperable.
Recommendations
For Apache Mesos versions prior to 1.1.3, update to version 1.1.3 or later.
For Apache Mesos versions 1.2.x prior to 1.2.2, update to version 1.2.2 or later.
For Apache Mesos versions 1.3.x prior to 1.3.1, update to version 1.3.1 or later.
For Apache Mesos version 1.4.0-dev, update to a stable version that includes the fix.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Mesos