org.apache.mesos:mesos
Maven6 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.mesos:mesospage 1 of 1
- CVE-2017-7687HIGHCVSS 7.5EG 7.5fixed in 1.1.3, 1.2.2 or 1.3.1, by version range2017-09-29
vulnerable: 1.3.0, 1.3.1-rc1
When handling a decoding failure for a malformed URL path of an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev might crash because the code accidentally calls inappropriate func…
- CVE-2017-9790HIGHCVSS 7.5EG 7.5fixed in 1.1.3, 1.2.2 or 1.3.1, by version range2017-09-29
vulnerable: 1.3.0, 1.3.1-rc1
When handling a libprocess message wrapped in an HTTP request, libprocess in Apache Mesos before 1.1.3, 1.2.x before 1.2.2, 1.3.x before 1.3.1, and 1.4.0-dev crashes if the request path is empty, because the parser assumes the request path…
- CVE-2018-11793HIGHCVSS 7.5EG 7.5fixed in 1.4.3, 1.5.2, 1.6.2 or 1.7.1, by version range2019-03-05
vulnerable: 1.7.0, 1.7.1-rc1
When parsing a JSON payload with deeply nested JSON structures, the parser in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.1, 1.6.0 to 1.6.1, and 1.7.0 might overflow the stack due to unbounded recursion. A malicious actor…
- CVE-2018-1330HIGHCVSS 7.5EG 7.5fixed in 1.6.02018-09-13
vulnerable: 1.4.0 ... 1.5.3 (7 versions)
When parsing a malformed JSON payload, libprocess in Apache Mesos versions 1.4.0 to 1.5.0 might crash due to an uncaught exception. Parsing chunked HTTP requests with trailers can lead to a libprocess crash too because of the mistakenly pl…
- CVE-2018-8023MEDIUMCVSS 5.9EG 5.9fixed in 1.4.2, 1.5.2 or 1.6.1, by version range2018-09-21
vulnerable: 1.6.0
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided sign…
- CVE-2019-0204HIGHCVSS 7.8EG 7.8fixed in 1.4.3, 1.5.3, 1.6.2 or 1.7.2, by version range2019-03-25
vulnerable: 1.7.0, 1.7.1, 1.7.1-rc1
A specifically crafted Docker image running under the root user can overwrite the init helper binary of the container runtime and/or the command executor in Apache Mesos versions pre-1.4.x, 1.4.0 to 1.4.2, 1.5.0 to 1.5.2, 1.6.0 to 1.6.1, a…
Check whether org.apache.mesos:mesos is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.mesos:mesos CVEs against the assets you own.
Book a Demo →