Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade munin | Aug 30, 2017 | Feb 22, 2017 |
| Amazon_linux | — | Upgrade munin | Apr 20, 2017 | Feb 22, 2017 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Feb 22, 2017 |
| Debian | — | Upgrade munin | Feb 27, 2017 | Feb 22, 2017 |
| Gentoo Linux | — | Upgrade net-analyzer/munin. | Oct 30, 2017 | Feb 22, 2017 |
| Suse | — | Upgrade munin-nodeUpgrade munin | Mar 7, 2017 | Feb 22, 2017 |
| Ubuntu | — | Upgrade munin | Mar 3, 2017 | Feb 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub