CVE-2016-7067

Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.
CSRF
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
redhatCNA
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 42%
Affected Products (NVD)
VendorProductVersion
mmonitmonit
𝑥
< 5.20.0
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
tildeslashmonit
5.20.0
CNA
Debian logo
Debian Releases
Debian Product
Codename
monit
bookworm
1:5.33.0-1
fixed
bullseye
1:5.27.2-1
fixed
jessie
no-dsa
sid
1:5.34.0-1
fixed
trixie
1:5.34.0-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
monit
artful
not-affected
bionic
not-affected
precise
ignored
trusty
Fixed 1:5.6-2ubuntu0.1
released
xenial
Fixed 1:5.16-2ubuntu0.1
released
yakkety
ignored
zesty
ignored