Known Vulnerabilities for Mesos by Apache
Listed below are 9 of the newest known vulnerabilities associated with "Mesos" by "Apache".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2019-5736 | runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc binary... | 8.6 - HIGH | 2019-02-11 | 2024-02-02 |
| CVE-2019-0204 | A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime... | 7.8 - HIGH | 2019-03-25 | 2023-11-07 |
| CVE-2018-1000421 | An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows atta... | 6.5 - MEDIUM | 2019-01-09 | 2023-11-07 |
| CVE-2018-1000420 | An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows atta... | 6.5 - MEDIUM | 2019-01-09 | 2023-11-07 |
| CVE-2018-11793 | When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2... | 7.5 - HIGH | 2019-03-05 | 2023-11-07 |
| CVE-2018-8023 | Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache ... | 5.9 - MEDIUM | 2018-09-21 | 2023-11-07 |
| CVE-2018-1330 | When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exce... | 7.5 - HIGH | 2018-09-13 | 2023-11-07 |
| CVE-2017-9790 | When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1... | 7.5 - HIGH | 2017-09-29 | 2023-11-07 |
| CVE-2017-7687 | When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x ... | 7.5 - HIGH | 2017-09-29 | 2023-11-07 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Apache | Mesos | 1.8.0 | dev | All | All |
| Application | Apache | Mesos | 1.7.2 | - | All | All |
| Application | Apache | Mesos | 1.7.2 | rc1 | All | All |
| Application | Apache | Mesos | 1.7.1 | - | All | All |
| Application | Apache | Mesos | 1.7.1 | rc1 | All | All |
| Application | Apache | Mesos | 1.7.1 | rc2 | All | All |
| Application | Apache | Mesos | 1.7.0 | All | All | All |
| Application | Apache | Mesos | 1.7.0 | - | All | All |
| Application | Apache | Mesos | 1.7.0 | rc1 | All | All |
| Application | Apache | Mesos | 1.7.0 | rc2 | All | All |
| Application | Apache | Mesos | 1.7.0 | rc3 | All | All |
| Application | Apache | Mesos | 1.6.2 | - | All | All |
| Application | Apache | Mesos | 1.6.2 | rc1 | All | All |
| Application | Apache | Mesos | 1.6.1 | All | All | All |
| Application | Apache | Mesos | 1.6.1 | - | All | All |
| Application | Apache | Mesos | 1.6.1 | rc1 | All | All |
| Application | Apache | Mesos | 1.6.1 | rc2 | All | All |
| Application | Apache | Mesos | 1.6.0 | All | All | All |
| Application | Apache | Mesos | 1.6.0 | - | All | All |
| Application | Apache | Mesos | 1.6.0 | rc1 | All | All |