Candidate: CVE-2016-7067 PublicDate: 2018-09-10 14:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7067 https://bitbucket.org/tildeslash/monit/commits/c6ec3820e627f85417053e6336de2987f2d863e3?at=master Description: Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service. Ubuntu-Description: It was discovered that the Monit web interface did not protect against cross-site request forgery (CSRF) attacks. If an authenticated user were tricked into visiting a malicious website while logged into Monit, a remote attacker could perform administrative actions. Notes: Bugs: Priority: medium Discovered-by: Assigned-to: ebarretto CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N [6.5 MEDIUM] Patches_monit: upstream: https://bitbucket.org/tildeslash/monit/commits/c6ec3820e627f85417053e6336de2987f2d863e3?at=master upstream_monit: released (1:5.20.0-1) precise_monit: ignored (reached end-of-life) precise/esm_monit: DNE (precise was needed) trusty_monit: released (1:5.6-2ubuntu0.1) trusty/esm_monit: released (1:5.6-2ubuntu0.1) vivid/stable-phone-overlay_monit: DNE vivid/ubuntu-core_monit: DNE xenial_monit: released (1:5.16-2ubuntu0.1) yakkety_monit: ignored (reached end-of-life) zesty_monit: ignored (reached end-of-life) artful_monit: not-affected bionic_monit: not-affected devel_monit: not-affected