Incorrect authorization in Tildeslash Monit - CVE-2022-26563
Published: August 24, 2023
Vulnerability identifier: #VU79960
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-26563
CWE-ID: CWE-863
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper PAM-authorization. A remote user can execute arbitrary code on the system.
Affected software
Tildeslash Monit
Amazon Linux AMI
Fedora
Ubuntu
monit (Ubuntu package)
monit
Amazon Linux AMI
Fedora
Ubuntu
monit (Ubuntu package)
monit
How to mitigate CVE-2022-26563
Install updates from vendor's website.
Tildeslash Monit - update to 5.31.0
monit (Ubuntu package) - update to Ubuntu Pro
monit - update to 5.2.5-3.12
monit - addressed in versions 5.30.0-2.el7, 5.33.0-1.el8
monit (Ubuntu package) - update to Ubuntu Pro
monit - update to 5.2.5-3.12
monit - addressed in versions 5.30.0-2.el7, 5.33.0-1.el8