Description
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-836-1 | munin security update |
Debian DSA |
DSA-3794-1 | munin security update |
EUVD |
EUVD-2017-15253 | Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user. |
Ubuntu USN |
USN-3215-1 | Munin vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:25:47.709Z
Reserved: 2017-02-22T00:00:00.000Z
Link: CVE-2017-6188
No data.
Status : Modified
Published: 2017-02-22T19:59:00.293
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-6188
No data.
OpenCVE Enrichment
No data.
Weaknesses
Debian DLA
Debian DSA
EUVD
Ubuntu USN