7.5
CVSSv3

CVE-2017-9790

Published: 29/09/2017 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos prior to 1.1.3, 1.2.x prior to 1.2.2, 1.3.x prior to 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path always starts with '/'. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.

Vulnerable Product Search on Vulmon Subscribe to Product

apache mesos 1.4.0-dev

apache mesos 1.3.0

apache mesos 1.3.1

apache mesos 1.2.0

apache mesos 1.2.1

apache mesos