CVE-2016-1000003

critical
Published 2016-10-07 · Modified 2026-05-06
CVSS v3
9.8
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.5
VIR risk
9.8

Description

Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code.

Predictions

Exploit likelihood
97%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/fedora-infra/mirrormanager2/commit/eb9b542bc818071b9eee41c3583b7e6e172b3a53.patch

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/fedora-infra/mirrormanager2/commit/2e227f6023477cbdbefd577f15d0846aa40c8775.patch

Application impact

VendorProductVersionsFixed
mirror_manager_projectmirror_manager{"endIncluding":"0.7.2"}

References

CWEs

CWE-94

Verify integrity in audit chain (admin only). AS-IS.