CVE-2017-6188

EUVD-2017-15253
Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 33%
Affected Products (NVD)
VendorProductVersion
munin-monitoringmunin
𝑥
< 2.0.30.1
munin-monitoringmunin
2.1.0 ≤
𝑥
< 2.999.9
debiandebian_linux
8.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
munin
bookworm
2.0.73-1
fixed
bullseye
2.0.67-3
fixed
sid
2.0.76-1
fixed
trixie
2.0.76-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
munin
precise
not-affected
trusty
Fixed 2.0.19-3ubuntu0.2
released
xenial
Fixed 2.0.25-2ubuntu0.16.04.2
released
yakkety
Fixed 2.0.25-2ubuntu0.16.10.2
released