CVE-2017-1000199: Tcmu-Runner Project Tcmu-Runner

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

tcmu-runner version 0.91 up to 1.20 is vulnerable to information disclosure in handler_qcow.so resulting in non-privileged users being able to check for existence of any file with root privileges.

Affected products

  • Tcmu-Runner Project Tcmu-Runner: version 0.9.1 only; version 0.9.2 only; version 0.9.3 only; version 0.9.4 only; version 1.0.5 only; version 1.1.0 only; …

Published 2017-11-17. Last modified 2026-06-17.