SB2017122610 - Fedora 27 update for monit
Published: December 26, 2017 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Cross-site request forgery (CVE-ID: CVE-2016-7067)
The vulnerability allows a remote non-authenticated attacker to manipulate data.
Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.
Remediation
Install update from vendor's website.