Ganglia is a distributed monitoring and cluster-management system with a modestly sized footprint centered on its web interface and collection daemons, which are deployed across academic and enterprise computing clusters. Its vulnerabilities recur through web-application input-handling classes such as cross-site scripting and authentication weaknesses, as well as memory-safety issues in its collection agents, and the platform's recurring exposure to public exploit tooling reflects the accessibility of monitoring interfaces to attackers seeking cluster reconnaissance and lateral movement. A meaningful share of its disclosures reach serious severity; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ganglia over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-3448HIGH Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown attack vectors. | Aug 6, 2012 | 7.5 | 38 | NO | YES |
CVE-2009-0241HIGH Stack-based buffer overflow in the process_path function in gmetad/server.c in Ganglia 3.1.1 allows remote attackers to cause a denial of service (crash) via a request to the gmeta | Jan 21, 2009 | 7.5 | 30 | NO | YES |
CVE-2024-52762MEDIUM A cross-site scripting (XSS) vulnerability in the component /master/header.php of Ganglia-web v3.73 to v3.76 allows attackers to execute arbitrary web scripts or HTML via a crafted | Nov 19, 2024 | 5.4 | 25 | NO | YES |
CVE-2015-6816CRITICAL ganglia-web before 3.7.1 allows remote attackers to bypass authentication. | Aug 9, 2017 | 9.8 | 25 | NO | NO |
CVE-2024-52763MEDIUM A cross-site scripting (XSS) vulnerability in the component /graph_all_periods.php of Ganglia-web v3.73 to v3.75 allows attackers to execute arbitrary web scripts or HTML via a cra | Nov 19, 2024 | 5.4 | 24 | NO | YES |
CVE-2019-20378MEDIUM ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php ce parameter. | Jan 11, 2020 | 6.1 | 22 | NO | NO |
CVE-2019-20379MEDIUM ganglia-web (aka Ganglia Web Frontend) through 3.7.5 allows XSS via the header.php cs parameter. | Jan 11, 2020 | 6.1 | 21 | NO | NO |
CVE-2002-2104HIGH graph.php in Ganglia PHP RRD Web Client 1.0.2 allows remote attackers to execute arbitrary commands via the command parameter, which is provided to the passthru function. | Dec 31, 2002 | 7.5 | 21 | NO | NO |
CVE-2013-6395MEDIUM Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter t | Dec 5, 2013 | 4.3 | 18 | NO | NO |
CVE-2011-3741MEDIUM Ganglia 3.1.7 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated | Sep 23, 2011 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ganglia.
Media articles that mention a CVE ID that affects a product developed by Ganglia — matched by CVE ID, not by vendor name.