org.apache.mesos:mesos
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.mesos:mesospage 1 of 1
- CVE-2017-7687HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.12017-09-29
vulnerable: 1.3.0, 1.3.1-rc1
When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate func…
- CVE-2017-9790HIGHCVSS 7.5EG 7.5✓ Fixed in 1.3.12017-09-29
vulnerable: 1.3.0, 1.3.1-rc1
When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path…
- CVE-2018-11793HIGHCVSS 7.5EG 7.5✓ Fixed in 1.7.12019-03-05
vulnerable: 1.7.0, 1.7.1-rc1
When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor…
- CVE-2018-1330HIGHCVSS 7.5EG 7.5✓ Fixed in 1.6.02018-09-13
vulnerable: 1.4.0 ... 1.5.3 (7 versions)
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly pl…
- CVE-2018-8023MEDIUMCVSS 5.9EG 5.9✓ Fixed in 1.6.12018-09-21
vulnerable: 1.6.0
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided sign…
- CVE-2019-0204HIGHCVSS 7.8EG 7.8✓ Fixed in 1.7.22019-03-25
vulnerable: 1.7.0, 1.7.1, 1.7.1-rc1
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, a…
Check whether org.apache.mesos:mesos is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.mesos:mesos CVEs against the assets you own.
Start Free Scan →