CVE-2017-6188

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
22/02/2017
Last modified:
20/04/2025

Description

Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www-data user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:munin-monitoring:munin:*:*:*:*:*:*:*:* 2.0.30.1 (excluding)
cpe:2.3:a:munin-monitoring:munin:*:*:*:*:*:*:*:* 2.1.0 (including) 2.999.9 (excluding)
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*