CVE-2020-36968
EUVD-2020-3088228.01.2026, 18:16
M/Monit 3.7.4 contains an authentication vulnerability that allows authenticated attackers to retrieve user password hashes through an administrative API endpoint. Attackers can send requests to the /api/1/admin/users/list and /api/1/admin/users/get endpoints to extract MD5 password hashes for all users.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| tildeslash | m\/monit | 3.7.4 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration