Описание
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (glances/exports/glances_cassandra/__init__.py) interpolates keyspace, table, and replication_factor configuration values directly into CQL statements without validation. A user with write access to glances.conf can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix.
| Релиз | Статус | Примечание |
|---|---|---|
| devel | needs-triage | |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/focal | needs-triage | |
| esm-apps/jammy | needs-triage | |
| esm-apps/noble | needs-triage | |
| esm-apps/resolute | needs-triage | |
| esm-apps/xenial | ignored | end of ESM support, was needs-triage |
| jammy | needs-triage | |
| noble | needs-triage |
Показывать по
Ссылки на источники
6.3 Medium
CVSS3
Связанные уязвимости
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix.
Glances is an open-source system cross-platform monitoring tool. Prior ...
Glances has CQL Injection in its Cassandra Export Module via Unsanitized Config Values
Уязвимость модуля экспорта Cassandra прикладного программного интерфейса инструмента мониторинга Glances, позволяющая нарушителю выполнить произвольный код
6.3 Medium
CVSS3