PT-2017-17886 · Apache · Apache Mesos

Published

2017-09-28

·

Updated

2022-05-13

·

CVE-2017-7687

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Mesos versions prior to 1.1.3 Apache Mesos versions 1.2.x prior to 1.2.2 Apache Mesos versions 1.3.x prior to 1.3.1 Apache Mesos version 1.4.0-dev
Description The issue arises when handling a decoding failure for a malformed URL path of an HTTP request. This can cause libprocess in Apache Mesos to crash due to the code accidentally calling an inappropriate function. As a result, a malicious actor can cause a denial of service of Mesos masters, rendering the Mesos-controlled cluster inoperable.
Recommendations For Apache Mesos versions prior to 1.1.3, update to version 1.1.3 or later. For Apache Mesos versions 1.2.x prior to 1.2.2, update to version 1.2.2 or later. For Apache Mesos versions 1.3.x prior to 1.3.1, update to version 1.3.1 or later. For Apache Mesos version 1.4.0-dev, update to a stable version that includes the fix.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-7687
GHSA-X869-784M-JMJ2

Affected Products

Apache Mesos