Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

openSUSE Cacti Moderate User Enumeration Flaw CVE-2024-27355

opensuse
Calendar Grey June 5, 2026
Dist Opensuse Esm H88
Update for openSUSE Cacti resolves moderate security issue from CVE-2024-27355 and enhances software stability.
An update that fixes one vulnerability is now available.

Description

This update for cacti fixes the following issues:

- Update to version 1.2.30+git457.e55c2aea:

* docs(changelog): add security fix refs for 1.2.31 (#7170)

* fix: Upgrade DOMPurify again for additional hardening (#7168)

* security: Ensure that reports does not work as guest (#7167)

* Update translation files

* security: GHSA-m7v2-f3xw-3qh7 - User Enumeration via Error Messages

(#7166)

* chore: Move around developers, rest in peace my friend (#7165)

* Import undefined variable (#7164)

* fix: guard api_plugin_moveup/movedown against NULL prior/next id

(1.2.x backport) (#7158)

* fix(correctness): loop-state leaks, chunk-aware poller CRC,

header-suppression and tree false-guards (1.2.x) (#7151)

* fix: Remove composer.lock (#7156)

* test: source-pattern coverage backfill for PR 7148, 7149, 7150 (#7153)

* fix: CVE-2024-27355 in phpseclib (#7155)

* chore: Update ChangeLogs (#7152)

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Backports SLE-15-SP7:

zypper in -t patch openSUSE-2026-189=1

Package List

- openSUSE Backports SLE-15-SP7 (noarch):

cacti-1.2.30+git457.e55c2aea-bp157.2.12.1

References

https://www.suse.com/security/cve/CVE-2024-27355.html

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:0189-1
Rating: moderate
Affected Products: openSUSE Backports SLE-15-SP7

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here