CVE-2017-9790: Use After Free
(updated )
When handling a libprocess message wrapped in an HTTP request, libprocess
in Apache Mesos crashes if the request path is empty, because the parser assumes the request path always starts with /
. A malicious actor can therefore cause a denial of service of Mesos masters rendering the Mesos-controlled cluster inoperable.
References
Detect and mitigate CVE-2017-9790 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →