CVE-2017-6188Improper Input Validation in Munin

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 66.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 13

Description

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

debiandebian/munin< munin 2.0.31-1 (bookworm)
NVDmunin-monitoring/munin2.1.02.999.9+1
Debianmunin-monitoring/munin< 2.0.31-1+3

Also affects: Debian Linux 8.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vpvg-79jp-cjw8: Munin before 22022-05-13
OSV
CVE-2017-6188: Munin before 22017-02-22

📋Vendor Advisories

2
Ubuntu
Munin vulnerability2017-03-02
Debian
CVE-2017-6188: munin - Munin before 2.999.6 has a local file write vulnerability when CGI graphs are en...2017

💬Community

3
Bugzilla
CVE-2017-6188 munin: Local file write vulnerability with CGI graphs enabled2017-02-22
Bugzilla
CVE-2017-6188 munin: Local file write vulnerability with CGI graphs enabled [epel-all]2017-02-22
Bugzilla
CVE-2017-6188 munin: Local file write vulnerability with CGI graphs enabled [fedora-all]2017-02-22