PT-2015-3294 · Ganglia · Ganglia-Web

Joseph Mingrone

·

Published

2015-09-07

·

Updated

2017-08-20

·

CVE-2015-6816

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ganglia-web versions prior to 3.7.1
Description The issue is related to a weakness in the authentication procedure of the Ganglia monitoring system's web interface, allowing remote attackers to bypass authentication. This can enable a remote attacker to circumvent the authentication process.
Recommendations For versions prior to 3.7.1, update to version 3.7.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the Ganglia-web interface until the update can be applied.

Exploit

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-01993
CVE-2015-6816
MGASA-2015-0375

Affected Products

Ganglia-Web