Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-munin | Aug 30, 2017 | Feb 22, 2017 | |
| Amazon_linux | — | amazon-linux-upgrade-munin | Apr 20, 2017 | Feb 22, 2017 |
| Arch Linux | arch-linux-upgrade-latest | Jul 11, 2025 | Feb 22, 2017 | |
| Debian | debian-upgrade-munin | Feb 27, 2017 | Feb 22, 2017 | |
| Gentoo Linux | gentoo-linux-upgrade-net-analyzer-munin | Oct 30, 2017 | Feb 22, 2017 | |
| Suse | — | suse-upgrade-muninsuse-upgrade-munin-node | Mar 7, 2017 | Feb 22, 2017 |
| Ubuntu | ubuntu-upgrade-munin | Mar 3, 2017 | Feb 22, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub