Описание
Security update for cacti, cacti-spine
This update for cacti, cacti-spine fixes the following issues:
cacti-spine 1.2.18:
- Fix missing time parameter on FROM_UNIXTIME function
cacti 1.2.18:
- CVE-2020-14424: Lack of escaping on template import can lead to XSS exposure under 'midwinter' theme (boo#1188188)
- Real time graphs can expose XSS issue
Список пакетов
SUSE Package Hub 12
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
SUSE Package Hub 15 SP3
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
openSUSE Leap 15.2
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
openSUSE Leap 15.3
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
Ссылки
- E-Mail link for openSUSE-SU-2021:1190-1
- SUSE Security Ratings
- SUSE Bug 1188188
- SUSE CVE CVE-2020-14424 page
Описание
Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.
Затронутые продукты
SUSE Package Hub 12:cacti-1.2.18-bp153.2.3.1
SUSE Package Hub 12:cacti-spine-1.2.18-bp153.2.3.1
SUSE Package Hub 15 SP3:cacti-1.2.18-bp153.2.3.1
SUSE Package Hub 15 SP3:cacti-spine-1.2.18-bp153.2.3.1
Ссылки
- CVE-2020-14424
- SUSE Bug 1188188