Denial of Service Vulnerability in Apache Mesos by Libprocess
CVE-2017-7687
7.5HIGH
What is CVE-2017-7687?
The vulnerability in Apache Mesos is caused by a flaw in the libprocess component, which mishandles decoding failures for malformed URL paths in HTTP requests. When invoked, this flaw can lead to crashes in Mesos masters, effectively rendering the associated Mesos-controlled cluster inoperable. A malicious actor exploiting this vulnerability could enforce a denial of service, impacting availability and operational continuity.
Affected Version(s)
Apache Mesos versions prior to 1.1.3
Apache Mesos 1.2.x before 1.2.2
Apache Mesos 1.3.x before 1.3.1