Bug 1218360 (CVE-2023-49084) - VUL-0: CVE-2023-49084: cacti: multiple vulnerabilities in link.php file
Summary: VUL-0: CVE-2023-49084: cacti: multiple vulnerabilities in link.php file
Status: RESOLVED FIXED
Alias: CVE-2023-49084
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/389152/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2023-12-22 14:41 UTC by SMASH SMASH
Modified: 2024-01-24 17:27 UTC (History)
3 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2023-12-22 14:41:47 UTC
Cacti is a robust performance and fault management framework and a frontend to RRDTool - a Time Series Database (TSDB). While using the detected SQL Injection and insufficient processing of the include file path, it is possible to execute arbitrary code on the server. Exploitation of the vulnerability is possible for an authorized user. The vulnerable component is the `link.php`. Impact of the vulnerability execution of arbitrary code on the server. 

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2023-49084
https://github.com/Cacti/cacti/security/advisories/GHSA-pfh9-gwm6-86vp

Patch:
https://github.com/Cacti/cacti/commit/c7c91bf4bdb87769351782b61cda6d89e8e82343
Comment 3 Andreas Stieger 2023-12-24 13:16:44 UTC
submitted
Comment 4 OBSbugzilla Bot 2023-12-24 15:35:01 UTC
This is an autogenerated message for OBS integration:
This bug (1218360) was mentioned in
https://build.opensuse.org/request/show/1134986 Factory / cacti
https://build.opensuse.org/request/show/1134987 Backports:SLE-12+Backports:SLE-15-SP4+Backports:SLE-15-SP5 / cacti+cacti-spine
Comment 5 OBSbugzilla Bot 2023-12-31 21:35:01 UTC
This is an autogenerated message for OBS integration:
This bug (1218360) was mentioned in
https://build.opensuse.org/request/show/1135899 Backports:SLE-12+Backports:SLE-15-SP5 / cacti+cacti-spine
Comment 6 Marcus Meissner 2024-01-24 17:04:59 UTC
openSUSE-SU-2024:0031-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1218360,1218366,1218378,1218379,1218380,1218381
CVE References: CVE-2023-49084,CVE-2023-49085,CVE-2023-49086,CVE-2023-49088,CVE-2023-50250,CVE-2023-51448
JIRA References: 
Sources used:
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    cacti-1.2.26-38.1, cacti-spine-1.2.26-32.1
Comment 7 Marcus Meissner 2024-01-24 17:05:26 UTC
openSUSE-SU-2024:0031-1: An update that fixes 6 vulnerabilities is now available.

Category: security (important)
Bug References: 1218360,1218366,1218378,1218379,1218380,1218381
CVE References: CVE-2023-49084,CVE-2023-49085,CVE-2023-49086,CVE-2023-49088,CVE-2023-50250,CVE-2023-51448
JIRA References: 
Sources used:
openSUSE Backports SLE-15-SP5 (src):    cacti-1.2.26-bp155.2.6.1, cacti-spine-1.2.26-bp155.2.6.1
SUSE Package Hub for SUSE Linux Enterprise 12 (src):    cacti-1.2.26-38.1, cacti-spine-1.2.26-32.1
Comment 8 Andreas Stieger 2024-01-24 17:27:35 UTC
done