3.3.3 (2017-07-24)

  • Fixed CVE-2017-11610. A vulnerability was found where an authenticatedclient can send a malicious XML-RPC request to supervisord that willrun arbitrary shell commands on the server. The commands will be run asthe same user as supervisord. Depending on how supervisord has beenconfigured, this may be root. Seehttps://github.com/Supervisor/supervisor/issues/964 for details.