Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2019-16723

Опубликовано: 23 сент. 2019
Источник: debian
EPSS Низкий

Описание

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
cactifixed1.2.7+ds1-1package
cactifixed1.2.2+ds1-2+deb10u2busterpackage
cactinot-affectedstretchpackage
cactinot-affectedjessiepackage

Примечания

  • vulnerability introduced in

  • https://github.com/Cacti/cacti/commit/cf73ae1a9f65b5a27d7f9d10c8e14835c3a76326 (release/1.0.0)

  • see Debian bug report for more information

  • https://github.com/Cacti/cacti/issues/2964

  • https://github.com/Cacti/cacti/commit/7a6a17252a1cbda180b61fff244cb3ce797d5264 (release/1.2.7)

  • https://github.com/Cacti/cacti/commit/c7cf4a26e4848872b48094e67f8d0a01dd7613d2 (release/1.2.7)

  • after further discussion, upstream issued a new fix which reverts previous commits

  • https://github.com/Cacti/cacti/commit/cfb0733597af97abc92270de4f47cbfa32f9ce8b (release/1.2.8)

  • which turned out to be insufficient to fix the issue, follow up patches:

  • https://github.com/Cacti/cacti/commit/9a1d2ec46d2dde23826c134ca70a0cd3bef43ee7 (release/1.2.8)

  • https://github.com/Cacti/cacti/commit/d5f98679a06aa96adfe04f60908f9108cfc9f7f7 (release/1.2.8)

  • https://github.com/Cacti/cacti/commit/4cecb19f6be8b84fa1c7b6450b66176007cb53df (release/1.2.8)

  • The original issue mentions only a bypass via graph_json.php but there are

  • additional permission checks missed while checking the issue fixed with the

  • upstream commits.

EPSS

Процентиль: 50%
0.00268
Низкий

Связанные уязвимости

CVSS3: 4.3
ubuntu
больше 6 лет назад

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

CVSS3: 4.3
nvd
больше 6 лет назад

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

github
больше 3 лет назад

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

CVSS3: 4.3
fstec
больше 6 лет назад

Уязвимость функции local_graph_id системы мониторинга сервера Cacti, связанная с обходом авторизации посредством использования ключа, контролируемого пользователем, позволяющая нарушителю получить доступ к конфиденциальным данным

suse-cvrf
почти 6 лет назад

Security update for cacti, cacti-spine

EPSS

Процентиль: 50%
0.00268
Низкий