Munin Monitoring maintains a network resource-monitoring and graphing platform with a focused product portfolio that has earned visibility within infrastructure-monitoring deployments. The vendor's vulnerability disclosures center on its core Munin monitoring agent and server, spanning a modest but durable exposure footprint. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Munin Monitoring over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2012-2104MEDIUM cgi-bin/munin-cgi-graph in Munin 2.x writes data to a log file without sanitizing non-printable characters, which might allow user-assisted remote attackers to inject terminal emul | Aug 26, 2012 | 6.8 | 33 | NO | YES |
CVE-2012-3513HIGH munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via t | Nov 21, 2012 | 9.3 | 28 | NO | NO |
CVE-2012-3512HIGH Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replac | Nov 21, 2012 | 7.2 | 24 | NO | NO |
CVE-2017-6188MEDIUM Munin before 2.999.6 has a local file write vulnerability when CGI graphs are enabled. Setting multiple upper_limit GET parameters allows overwriting any file accessible to the www | Feb 22, 2017 | 5.5 | 21 | NO | NO |
CVE-2012-4678MEDIUM munin-cgi-graph for Munin 2.0 rc4 does not delete temporary files, which allows remote attackers to cause a denial of service (disk consumption) via many requests to an image with | Aug 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-2147MEDIUM munin-cgi-graph in Munin 2.0 rc4 allows remote attackers to cause a denial of service (disk or memory consumption) via many image requests with large values in the (1) size_x or (2 | Aug 26, 2012 | 5.0 | 18 | NO | NO |
CVE-2013-6048MEDIUM The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the m | Dec 13, 2013 | 5.0 | 15 | NO | NO |
CVE-2013-6359MEDIUM Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph | Dec 13, 2013 | 4.3 | 14 | NO | NO |
The qmailscan plugin for Munin 1.4.5 allows local users to overwrite arbitrary files via a symlink attack on temporary files with predictable names. | Aug 26, 2012 | 1.2 | 13 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Munin Monitoring.
Media articles that mention a CVE ID that affects a product developed by Munin Monitoring — matched by CVE ID, not by vendor name.