Explore top 10 tips to secure your open-source projects now. Read More
×
Multiple security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in cross-site scripting, SQL injection, or command injection. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4048-1
Multiple security vulnerabilities have been discovered in Cacti, a web interface for graphing of monitoring systems, which could result in cross-site scripting, SQL injection, or command injection. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5862-1
Cacti could be made to crash or run programs if it received specially crafted network traffic.. ========================================================================== Ubuntu Security Notice USN-7226-1 January 23, 2025 cacti vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS Summary: Cacti could be made to crash or run programs if it received specially crafted network traffic. Software Description: - cacti: web interface for graphing of monitoring systems Details: It was discovered that Cacti did not properly sanitize the 'poller_id' parameter in the "remote_agent.php" file. A remote attacker could possibly use this issue to achieve remote code execution. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS cacti 1.2.19+ds1-2ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 20.04 LTS cacti 1.2.10+ds1-1ubuntu1.1+esm2 Available with Ubuntu Pro Ubuntu 18.04 LTS cacti 1.1.38+ds1-1ubuntu0.1~esm4 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7226-1 CVE-2022-46169 . Certain vulnerabilities in cacti may lead to system failures or unintended code execution from unprocessed network data. It's crucial to update the software to maintain security integrity.. Cacti security, Ubuntu updates, network traffic, remote code issue, software vulnerabilities. . LinuxSecurity.com Team
Cacti, a web interface for graphing of monitoring systems, was vulnerable. CVE-2022-41444 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3884-1
An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for cacti, cacti-spine ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0276-1 Rating: important References: #1224229 #1224230 #1224231 #1224235 #1224236 #1224237 #1224238 #1224239 #1224240 #1224241 Cross-References: CVE-2024-25641 CVE-2024-27082 CVE-2024-29894 CVE-2024-31443 CVE-2024-31444 CVE-2024-31445 CVE-2024-31458 CVE-2024-31459 CVE-2024-31460 CVE-2024-34340 Affected Products: openSUSE Backports SLE-15-SP6 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for cacti, cacti-spine fixes the following issues: - cacti 1.2.27: * CVE-2024-34340: Authentication Bypass when using using older password hashes (boo#1224240) * CVE-2024-25641: RCE vulnerability when importing packages (boo#1224229) * CVE-2024-31459: RCE vulnerability when plugins include files (boo#1224238) * CVE-2024-31460: SQL Injection vulnerability when using tree rules through Automation API (boo#1224239) * CVE-2024-29894: XSS vulnerability when using JavaScript based messaging API (boo#1224231) * CVE-2024-31458: SQL Injection vulnerability when using form templates (boo#1224241) * CVE-2024-31444: XSS vulnerability when reading tree rules with Automation API (boo#1224236) * CVE-2024-31443: XSS vulnerability when managing data queries (boo#1224235) * CVE-2024-31445: SQL Injection vulnerability when retrieving graphs using Automation API (boo#1224237) * CVE-2024-27082: XSS vulnerability when managing trees (boo#1224230) * Improve PHP 8.3 support * When importing packages via command line, datasource profile could not be selected * When changing password, returning to previous page does not always work * When using LDAP authentication the first time, warnings may appear in logs * When editing/viewing devices, add IPv6 info to hostname tooltip * Improve speed of polling when Boost is enabled * Improve support for Half-Hour time zones * When user session not found, device lists can be incorrectly returned * On import, legacy templates may generate warnings * Improve support for alternate locations of Ping * Improve PHP 8.1 support for Installer * Fix issues with number formatting * Improve PHP 8.1 support when SpikeKill is run first time * Improve PHP 8.1 support for SpikeKill * When using Chinese to search for graphics, garbled characters appear. * When importing templates, preview mode will not always load * When remote poller is installed, MySQL TimeZone DB checks are not performed * When Remote Poller installation completes, no finish button is shown * Unauthorized agents should be recorded into logs * Poller cache may not always update if hostname changes * When using CMD poller, Failure and Recovery dates may have incorrect values * Saving a Tree can cause the tree to become unpublished * Web Basic Authentication does not record user logins * When using Accent-based languages, translations may not work properly * Fix automation expressions for device rules * Improve PHP 8.1 Support during fresh install with boost * Add a device "enabled/disabled" indicator next to the graphs * Notify the admin periodically when a remote data collector goes into heartbeat status * Add template for Aruba Clearpass * Add fliter/sort of Device Templates by Graph Templates - cacti-spine 1.2.27: * Restore AES Support Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods likeYaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP6: zypper in -t patch openSUSE-2024-276=1 Package List: - openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64): cacti-spine-1.2.27-bp156.2.3.1 cacti-spine-debuginfo-1.2.27-bp156.2.3.1 cacti-spine-debugsource-1.2.27-bp156.2.3.1 - openSUSE Backports SLE-15-SP6 (noarch): cacti-1.2.27-bp156.2.3.1 References: https://www.suse.com/security/cve/CVE-2024-25641.html https://www.suse.com/security/cve/CVE-2024-27082.html https://www.suse.com/security/cve/CVE-2024-29894.html https://www.suse.com/security/cve/CVE-2024-31443.html https://www.suse.com/security/cve/CVE-2024-31444.html https://www.suse.com/security/cve/CVE-2024-31445.html https://www.suse.com/security/cve/CVE-2024-31458.html https://www.suse.com/security/cve/CVE-2024-31459.html https://www.suse.com/security/cve/CVE-2024-31460.html https://www.suse.com/security/cve/CVE-2024-34340.html https://bugzilla.suse.com/1224229 https://bugzilla.suse.com/1224230 https://bugzilla.suse.com/1224231 https://bugzilla.suse.com/1224235 https://bugzilla.suse.com/1224236 https://bugzilla.suse.com/1224237 https://bugzilla.suse.com/1224238 https://bugzilla.suse.com/1224239 https://bugzilla.suse.com/1224240 https://bugzilla.suse.com/1224241 . This bulletin highlights a critical patch for Fedora, focusing on various security flaws within the Drupal framework.. openSUSE Update, Cacti Security Fixes, Cacti Advisory, cacti-spine Vulnerability Fixes, openSUSE Security Update. . Severity: Important. LinuxSecurity.com Team
An update that fixes 10 vulnerabilities is now available. . openSUSE Security Update: Security update for cacti, cacti-spine ______________________________________________________________________________ Announcement ID: openSUSE-SU-2024:0274-1 Rating: important References: #1224229 #1224230 #1224231 #1224235 #1224236 #1224237 #1224238 #1224239 #1224240 #1224241 Cross-References: CVE-2024-25641 CVE-2024-27082 CVE-2024-29894 CVE-2024-31443 CVE-2024-31444 CVE-2024-31445 CVE-2024-31458 CVE-2024-31459 CVE-2024-31460 CVE-2024-34340 Affected Products: openSUSE Backports SLE-15-SP5 ______________________________________________________________________________ An update that fixes 10 vulnerabilities is now available. Description: This update for cacti, cacti-spine fixes the following issues: - cacti 1.2.27: * CVE-2024-34340: Authentication Bypass when using using older password hashes (boo#1224240) * CVE-2024-25641: RCE vulnerability when importing packages (boo#1224229) * CVE-2024-31459: RCE vulnerability when plugins include files (boo#1224238) * CVE-2024-31460: SQL Injection vulnerability when using tree rules through Automation API (boo#1224239) * CVE-2024-29894: XSS vulnerability when using JavaScript based messaging API (boo#1224231) * CVE-2024-31458: SQL Injection vulnerability when using form templates (boo#1224241) * CVE-2024-31444: XSS vulnerability when reading tree rules with Automation API (boo#1224236) * CVE-2024-31443: XSS vulnerability when managing data queries (boo#1224235) * CVE-2024-31445: SQL Injection vulnerability when retrieving graphs using Automation API (boo#1224237) * CVE-2024-27082: XSS vulnerability when managing trees (boo#1224230) * Improve PHP 8.3 support * When importing packages via command line, datasource profile could not be selected * When changing password, returning to previous page does not always work * When using LDAP authentication the first time, warnings may appear in logs * When editing/viewing devices, add IPv6 info to hostname tooltip * Improve speed of polling when Boost is enabled * Improve support for Half-Hour time zones * When user session not found, device lists can be incorrectly returned * On import, legacy templates may generate warnings * Improve support for alternate locations of Ping * Improve PHP 8.1 support for Installer * Fix issues with number formatting * Improve PHP 8.1 support when SpikeKill is run first time * Improve PHP 8.1 support for SpikeKill * When using Chinese to search for graphics, garbled characters appear. * When importing templates, preview mode will not always load * When remote poller is installed, MySQL TimeZone DB checks are not performed * When Remote Poller installation completes, no finish button is shown * Unauthorized agents should be recorded into logs * Poller cache may not always update if hostname changes * When using CMD poller, Failure and Recovery dates may have incorrect values * Saving a Tree can cause the tree to become unpublished * Web Basic Authentication does not record user logins * When using Accent-based languages, translations may not work properly * Fix automation expressions for device rules * Improve PHP 8.1 Support during fresh install with boost * Add a device "enabled/disabled" indicator next to the graphs * Notify the admin periodically when a remote data collector goes into heartbeat status * Add template for Aruba Clearpass * Add fliter/sort of Device Templates by Graph Templates - cacti-spine 1.2.27: * Restore AES Support Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods likeYaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Backports SLE-15-SP5: zypper in -t patch openSUSE-2024-274=1 Package List: - openSUSE Backports SLE-15-SP5 (aarch64 i586 ppc64le s390x x86_64): cacti-spine-1.2.27-bp155.2.9.1 - openSUSE Backports SLE-15-SP5 (noarch): cacti-1.2.27-bp155.2.9.1 References: https://www.suse.com/security/cve/CVE-2024-25641.html https://www.suse.com/security/cve/CVE-2024-27082.html https://www.suse.com/security/cve/CVE-2024-29894.html https://www.suse.com/security/cve/CVE-2024-31443.html https://www.suse.com/security/cve/CVE-2024-31444.html https://www.suse.com/security/cve/CVE-2024-31445.html https://www.suse.com/security/cve/CVE-2024-31458.html https://www.suse.com/security/cve/CVE-2024-31459.html https://www.suse.com/security/cve/CVE-2024-31460.html https://www.suse.com/security/cve/CVE-2024-34340.html https://bugzilla.suse.com/1224229 https://bugzilla.suse.com/1224230 https://bugzilla.suse.com/1224231 https://bugzilla.suse.com/1224235 https://bugzilla.suse.com/1224236 https://bugzilla.suse.com/1224237 https://bugzilla.suse.com/1224238 https://bugzilla.suse.com/1224239 https://bugzilla.suse.com/1224240 https://bugzilla.suse.com/1224241 . Addressing 10 critical vulnerabilities in openSUSE Cacti offerings through the recent essential security patch. Discover the specifics.. openSUSE Updates, Cacti Security, Cacti Advisory. . Severity: Important. LinuxSecurity.com Team
Several security issues were fixed in Cacti.. ========================================================================== Ubuntu Security Notice USN-6969-1 August 20, 2024 cacti vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS - Ubuntu 20.04 LTS - Ubuntu 18.04 LTS - Ubuntu 16.04 LTS - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Cacti. Software Description: - cacti: web interface for graphing of monitoring systems Details: It was discovered that Cacti did not properly apply checks to the "Package Import" feature. An attacker could possibly use this issue to perform arbitrary code execution. This issue only affected Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-25641) It was discovered that Cacti did not properly sanitize values when using javascript based API. A remote attacker could possibly use this issue to inject arbitrary javascript code resulting into cross-site scripting vulnerability. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-29894) It was discovered that Cacti did not properly sanitize values when managing data queries. A remote attacker could possibly use this issue to inject arbitrary javascript code resulting into cross-site scripting vulnerability. (CVE-2024-31443) It was discovered that Cacti did not properly sanitize values when reading tree rules with Automation API. A remote attacker could possibly use this issue to inject arbitrary javascript code resulting into cross-site scripting vulnerability. (CVE-2024-31444) It was discovered that Cacti did not properly sanitize "get_request_var('filter')" values in the "api_automation.php" file. A remote attacker could possibly use this issue to perform SQL injection attacks. This issue only affected Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-31445) It was discovered that Cacti didnot properly sanitize data stored in "form_save()" function in the "graph_template_inputs.php" file. A remote attacker could possibly use this issue to perform SQL injection attacks. (CVE-2024-31458) It was discovered that Cacti did not properly validate the file urls from the lib/plugin.php file. An attacker could possibly use this issue to perform arbitrary code execution. (CVE-2024-31459) It was discovered that Cacti did not properly validate the data stored in the "automation_tree_rules.php". A remote attacker could possibly use this issue to perform SQL injection attacks. This issue only affected Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-31460) It was discovered that Cacti did not properly verify the user password. An attacker could possibly use this issue to bypass authentication mechanism. This issue only affected Ubuntu 24.04 LTS, Ubuntu 22.04 LTS, Ubuntu 20.04 LTS and Ubuntu 18.04 LTS. (CVE-2024-34360) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS cacti 1.2.26+ds1-1ubuntu0.1 Ubuntu 22.04 LTS cacti 1.2.19+ds1-2ubuntu1.1 Ubuntu 20.04 LTS cacti 1.2.10+ds1-1ubuntu1.1 Ubuntu 18.04 LTS cacti 1.1.38+ds1-1ubuntu0.1~esm3 Available with Ubuntu Pro Ubuntu 16.04 LTS cacti 0.8.8f+ds1-4ubuntu4.16.04.2+esm2 Available with Ubuntu Pro Ubuntu 14.04 LTS cacti 0.8.8b+dfsg-5ubuntu0.2+esm2 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6969-1 CVE-2024-25641, CVE-2024-29894, CVE-2024-31443, CVE-2024-31444, CVE-2024-31445, CVE-2024-31458, CVE-2024-31459, CVE-2024-31460, CVE-2024-34340 Package Information: https://launchpad.net/ubuntu/+source/cacti/1.2.26+ds1-1ubuntu0.1 https://launchpad.net/ubuntu/+source/cacti/1.2.19+ds1-2ubuntu1.1 https://launchpad.net/ubuntu/+source/cacti/1.2.10+ds1-1ubuntu1.1 . Cacti vulnerability report highlights issues impacting various Ubuntu versions. Ensure to implement updates without delay.. Cacti Security, Ubuntu Advisory, Code Execution, Cross-Site Scripting, SQL Injection. . Severity: Critical. LinuxSecurity.com Team
Cacti could be made to crash if it received specially crafted input.. ========================================================================== Ubuntu Security Notice USN-6720-1 April 02, 2024 cacti vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 22.04 LTS (Available with Ubuntu Pro) Summary: Cacti could be made to crash if it received specially crafted input. Software Description: - cacti: web interface for graphing of monitoring systems Details: Kentaro Kawane discovered that Cacti incorrectly handled user provided input sent through request parameters to the graph_view.php script. A remote authenticated attacker could use this issue to perform SQL injection attacks. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 22.04 LTS (Available with Ubuntu Pro): cacti 1.2.19+ds1-2ubuntu1+esm1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-6720-1 CVE-2023-39361 . Succulents might fail upon specially designed input. Distant threat actors may take advantage of this vulnerability. Discover the fix today.. Critical Cacti Vulnerability, SQL Injection Risk, Ubuntu Security Advisory. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.