Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:1190-1

Опубликовано: 25 авг. 2021
Источник: suse-cvrf

Описание

Security update for cacti, cacti-spine

This update for cacti, cacti-spine fixes the following issues:

cacti-spine 1.2.18:

  • Fix missing time parameter on FROM_UNIXTIME function

cacti 1.2.18:

  • CVE-2020-14424: Lack of escaping on template import can lead to XSS exposure under 'midwinter' theme (boo#1188188)
  • Real time graphs can expose XSS issue

Список пакетов

SUSE Package Hub 12
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
SUSE Package Hub 15 SP3
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
openSUSE Leap 15.2
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1
openSUSE Leap 15.3
cacti-1.2.18-bp153.2.3.1
cacti-spine-1.2.18-bp153.2.3.1

Описание

Cacti before 1.2.18 allows remote attackers to trigger XSS via template import for the midwinter theme.


Затронутые продукты
SUSE Package Hub 12:cacti-1.2.18-bp153.2.3.1
SUSE Package Hub 12:cacti-spine-1.2.18-bp153.2.3.1
SUSE Package Hub 15 SP3:cacti-1.2.18-bp153.2.3.1
SUSE Package Hub 15 SP3:cacti-spine-1.2.18-bp153.2.3.1

Ссылки