Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Debian: DLA-3252-1 Critical: Cacti Information Disclosure and Code Exec

debian lts
Calendar Grey December 31, 2022
Dist Debian Esm H88
A range of vulnerabilities within Cacti could result in unauthorized data exposure, execution of malicious code from a distance, and circumvention of authentication mechanisms.
Multiple security vulnerabilities were discovered in cacti, a web interface for graphing of monitoring systems, which may result in information disclosure, authentication bypass, o...

Summary

Askar discovered that an authenticated guest user with the graph
real-time privilege could execute arbitrary code on a server running
Cacti, via shell meta-characters in a cookie.

CVE-2020-23226

Jing Chen discovered multiple Cross Site Scripting (XSS)
vulnerabilities in several pages, which can lead to information
disclosure.

CVE-2020-25706

joelister discovered an Cross Site Scripting (XSS) vulnerability in
templates_import.php, which can lead to information disclosure.

CVE-2022-0730

It has been discovered that Cacti authentication can be bypassed
when LDAP anonymous binding is enabled.

CVE-2022-46169

Stefan Schiller discovered a command injection vulnerability,
allowing an unauthenticated user to execute arbitrary code on a
server running Cacti, if a specific data source was selected (which
is likely the case on a production instance) for any monitored
device.

For Debian 10 buster, these problems have been fixed in version
1.2.2+ds1-2+deb10u5.

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: cacti
Version: 1.2.2+ds1-2+deb10u5
CVE ID: CVE-2020-8813 CVE-2020-23226 CVE-2020-25706 CVE-2022-0730
Debian Bug: 951832 1008693 1025648

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here