Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

openSUSE 12: 2024:0031-1 important: Addressing Cacti SQL Threats

opensuse
Calendar Grey January 24, 2024
Dist Opensuse Esm H88
Cacti has launched its latest patch that targets major security vulnerabilities, specifically those related to SQL Injection and XSS in openSUSE setups
An update that fixes 6 vulnerabilities is now available

Description

This update for cacti, cacti-spine fixes the following issues:

cacti-spine 1.2.26:

* Fix: Errors when uptime OID is not present

* Fix: MySQL reconnect option is depreciated

* Fix: Spine does not check a host with no poller items

* Fix: Poller may report the wrong number of devices polled

* Feature: Allow users to override the threads setting at the command line

* Feature: Allow spine to run in ping-only mode

cacti 1.2.26:

* CVE-2023-50250: XSS vulnerability when importing a template file

(boo#1218380)

* CVE-2023-49084: RCE vulnerability when managing links (boo#1218360)

* CVE-2023-49085: SQL Injection vulnerability when managing poller devices

(boo#1218378)

* CVE-2023-49086: XSS vulnerability when adding new devices (boo#1218366)

* CVE-2023-49088: XSS vulnerability when viewing data sources in debug

mode (boo#1218379)

* CVE-2023-51448: SQL Injection vulnerability when managing SNMP

Notification Receivers...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP5:

zypper in -t patch openSUSE-2024-31=1

- SUSE Package Hub for SUSE Linux Enterprise 12:

zypper in -t patch openSUSE-2024-31=1

Package List

- openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64):

cacti-spine-1.2.26-bp155.2.6.1

- openSUSE Backports SLE-15-SP5 (noarch):

cacti-1.2.26-bp155.2.6.1

- SUSE Package Hub for SUSE Linux Enterprise 12 (aarch64 ppc64le s390x x86_64):

cacti-spine-1.2.26-32.1

- SUSE Package Hub for SUSE Linux Enterprise 12 (noarch):

cacti-1.2.26-38.1

References

https://www.suse.com/security/cve/CVE-2023-49084.html

https://www.suse.com/security/cve/CVE-2023-49085.html

https://www.suse.com/security/cve/CVE-2023-49086.html

https://www.suse.com/security/cve/CVE-2023-49088.html

https://www.suse.com/security/cve/CVE-2023-50250.html

https://www.suse.com/security/cve/CVE-2023-51448.html

https://bugzilla.suse.com/1218360

https://bugzilla.suse.com/1218366

https://bugzilla.suse.com/1218378

https://bugzilla.suse.com/1218379

https://bugzilla.suse.com/1218380

https://bugzilla.suse.com/1218381

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2024:0031-1
Rating: important
Affected Products: SUSE Linux Enterprise High Performance Computing 12 SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12-SP3 SUSE Linux Enterprise Server 12-SP4 SUSE Linux Enterprise Server 12-SP5 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12-SP3 SUSE Linux Enterprise Server for SAP Applications 12-SP4 SUSE Linux Enterprise Server for SAP Applications 12-SP5 SUSE Package Hub for SUSE Linux Enterprise 12 openSUSE Backports SLE-15-SP5 .

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here