CVE-2022-26563

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-26563
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-26563.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-26563
Downstream
Published
2023-07-18T14:15:11Z
Modified
2025-10-21T07:01:28.515631Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Tildeslash Monit before 5.31.0, allows remote attackers to gain escilated privlidges due to improper PAM-authorization.

References

Affected packages

Git / bitbucket.org/tildeslash/monit

Affected ranges

Type
GIT
Repo
https://bitbucket.org/tildeslash/monit
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
6ecaab1d375f33165fe98d06d92f36c949c0ea11

Affected versions

Other

release-5-10-0
release-5-11-0
release-5-12-0
release-5-12-1
release-5-12-2
release-5-13-0
release-5-14-0
release-5-15-0
release-5-16-0
release-5-17-0
release-5-17-1
release-5-18-0
release-5-19-0
release-5-20-0
release-5-21-0
release-5-22-0
release-5-23-0
release-5-24-0
release-5-25-0
release-5-25-1
release-5-25-2
release-5-25-3
release-5-26-0
release-5-27-0
release-5-27-1
release-5-27-2
release-5-28-0
release-5-28-1
release-5-29-0
release-5-30-0
release-5-31-0
release-5-7
release-5-8
release-5-8-1
release-5-8-2
release-5-9-0

Database specific

vanir_signatures

[
    {
        "deprecated": false,
        "source": "https://bitbucket.org/tildeslash/monit@6ecaab1d375f33165fe98d06d92f36c949c0ea11",
        "id": "CVE-2022-26563-91ef866e",
        "signature_version": "v1",
        "target": {
            "file": "src/util.c"
        },
        "signature_type": "Line",
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "331168297561752226102267204412189674683",
                "181868434140535734383861704323782969498",
                "125843111526877862435972730749317177312",
                "59566004903050237551622989984586804288",
                "18648906668876949094318836248691963820",
                "124052130359031075612308104356858303489"
            ]
        }
    },
    {
        "deprecated": false,
        "source": "https://bitbucket.org/tildeslash/monit@6ecaab1d375f33165fe98d06d92f36c949c0ea11",
        "id": "CVE-2022-26563-fdac35b9",
        "signature_version": "v1",
        "target": {
            "function": "PAMcheckPasswd",
            "file": "src/util.c"
        },
        "signature_type": "Function",
        "digest": {
            "function_hash": "250226565052614570592318414475633464608",
            "length": 469.0
        }
    }
]