OPENSUSE-SU-2020:0272-1
Vulnerability Summary
Timeline
Description
Security update for cacti, cacti-spine This update for cacti, cacti-spine fixes the following issues: cacti-spine was updated to version 1.2.9. Security issues fixed: - CVE-2009-4112: Fixed a privilege escalation (bsc#1122535). - CVE-2018-20723: Fixed a cross-site scripting (XSS) vulnerability (bsc#1122245). - CVE-2018-20724: Fixed a cross-site scripting (XSS) vulnerability (bsc#1122244). - CVE-2018-20725: Fixed a privilege escalation that could occur under certain conditions (bsc#1122535). - CVE-2018-20726: Fixed a cross-site scripting (XSS) vulnerability (bsc#1122242). - CVE-2019-16723: Fixed an authentication bypass vulnerability. - CVE-2019-17357: Fixed an SQL injection vulnerability (bsc#1158990). - CVE-2019-17358: Fixed an unsafe deserialization in sanitize_unserialize_selected_items (bsc#1158992). - CVE-2020-7106: Fixed a potential cross-site scripting (XSS) vulnerability (bsc#1163749). - CVE-2020-7237: Fixed a remote code execution that affected privileged users via shell metacharacters in the Performance Boost Debug Log field (bsc#1161297). Non-security issues fixed: - Fixed missing packages php-json, php-ctype, and php-gd in cacti.spec (boo#1101024). - Fixed Apache2.4 and Apache2.2 runtime configuration issue (boo#1101139).
Affected Systems
- opensuse•cacti-spine&distro=openSUSE Leap 15.1
< 1.2.9-lp151.3.3.1
- opensuse•cacti&distro=openSUSE Leap 15.1
< 1.2.9-lp151.3.3.1
References (23)
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/QJH5OTPHSPMFV4CORKBXMWKMQWVD3CC5/
- https://bugzilla.suse.com/1082318
- https://bugzilla.suse.com/1101024
- https://bugzilla.suse.com/1101139
- https://bugzilla.suse.com/1122242
- https://bugzilla.suse.com/1122243
- https://bugzilla.suse.com/1122244
- https://bugzilla.suse.com/1122245
- https://bugzilla.suse.com/1122535
- https://bugzilla.suse.com/1158990
- https://bugzilla.suse.com/1158992
- https://bugzilla.suse.com/1161297
- https://bugzilla.suse.com/1163749
- https://www.suse.com/security/cve/CVE-2009-4112
- https://www.suse.com/security/cve/CVE-2018-20723
- https://www.suse.com/security/cve/CVE-2018-20724
- https://www.suse.com/security/cve/CVE-2018-20725
- https://www.suse.com/security/cve/CVE-2018-20726
- https://www.suse.com/security/cve/CVE-2019-16723
- https://www.suse.com/security/cve/CVE-2019-17357
- https://www.suse.com/security/cve/CVE-2019-17358
- https://www.suse.com/security/cve/CVE-2020-7106
- https://www.suse.com/security/cve/CVE-2020-7237