Vulnerabilities > Munin Monitoring > Munin > 2.0.beta4

DATE CVE VULNERABILITY TITLE RISK
2012-11-21 CVE-2012-3513 Permissions, Privileges, and Access Controls vulnerability in Munin-Monitoring Munin
munin-cgi-graph in Munin before 2.0.6, when running as a CGI module under Apache, allows remote attackers to load new configurations and create files in arbitrary directories via the logdir command.
network
munin-monitoring CWE-264
critical
9.3
2012-11-21 CVE-2012-3512 Permissions, Privileges, and Access Controls vulnerability in Munin-Monitoring Munin
Munin before 2.0.6 stores plugin state files that run as root in the same group-writable directory as non-root plugins, which allows local users to execute arbitrary code by replacing a state file, as demonstrated using the smart_ plugin.
local
low complexity
munin-monitoring CWE-264
7.2