Skip to main content

Vendor/product archive

apache / mesos CVEs

Beta · best-effort

9 CVEs tagged to apache / mesos0 Critical, 6 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2019-0204

Published Mar 25, 2019

A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11793

Published Mar 5, 2019

When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might over…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1000421

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test conn…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000420

Published Jan 9, 2019

An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials I…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-8023

Published Sep 21, 2018

Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comp…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1330

Published Sep 13, 2018

When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-9790

Published Sep 29, 2017

When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the reques…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7687

Published Sep 29, 2017

When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1