CVE-2014-6409: CSRF
Published Oct 6, 2014
·Updated
Cross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of administrators for requests that change user passwords via the fullname and password parameters to /admin/users/update.
Affected Software
1 affected component
Mmonit M\/monit<=3.3.2
Event History
Oct 6, 2014
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-6409?
CVE-2014-6409 has a medium severity rating due to its potential impact on administrative authentication.
2
How do I fix CVE-2014-6409?
To fix CVE-2014-6409, upgrade to M/Monit version 3.3.3 or later.
3
What is the attack vector for CVE-2014-6409?
The attack vector for CVE-2014-6409 is through cross-site request forgery (CSRF) targeting the admin user password update functionality.
4
Who is affected by CVE-2014-6409?
CVE-2014-6409 affects users of M/Monit versions 3.3.2 and earlier.
5
What can attackers do with CVE-2014-6409?
Attackers exploiting CVE-2014-6409 can hijack the authentication of administrators and change user passwords.