Bug 1224231 (CVE-2024-29894) - VUL-0: CVE-2024-29894: cacti: residual cross-site scripting vulnerability caused by incomplete fix
Summary: VUL-0: CVE-2024-29894: cacti: residual cross-site scripting vulnerability cau...
Status: RESOLVED FIXED
Alias: CVE-2024-29894
Product: openSUSE Distribution
Classification: openSUSE
Component: Security (show other bugs)
Version: Leap 15.6
Hardware: Other Other
: P3 - Medium : Normal (vote)
Target Milestone: ---
Assignee: Security Team bot
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/405104/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2024-05-14 18:03 UTC by SMASH SMASH
Modified: 2024-05-15 19:31 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description SMASH SMASH 2024-05-14 18:03:52 UTC
Cacti provides an operational monitoring and fault management framework. Versions of Cacti prior to 1.2.27 contain a residual cross-site scripting vulnerability caused by an incomplete fix for CVE-2023-50250. `raise_message_javascript` from `lib/functions.php` now uses purify.js to fix CVE-2023-50250 (among others). However, it still generates the code out of unescaped PHP variables `$title` and `$header`. If those variables contain single quotes, they can be used to inject JavaScript code. An attacker exploiting this vulnerability could execute actions on behalf of other users. This ability to impersonate users could lead to unauthorized changes to settings. Version 1.2.27 fixes this issue.

References:
https://github.com/Cacti/cacti/security/advisories/GHSA-xwqc-7jc4-xm73
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-29894
https://www.cve.org/CVERecord?id=CVE-2024-29894
https://github.com/Cacti/cacti/security/advisories/GHSA-grj5-8fcj-34gh
Comment 2 OBSbugzilla Bot 2024-05-14 19:25:06 UTC
This is an autogenerated message for OBS integration:
This bug (1224231) was mentioned in
https://build.opensuse.org/request/show/1174071 Factory / cacti
https://build.opensuse.org/request/show/1174072 Backports:SLE-12+Backports:SLE-15-SP5 / cacti+cacti-spine
Comment 3 OBSbugzilla Bot 2024-05-14 20:55:04 UTC
This is an autogenerated message for OBS integration:
This bug (1224231) was mentioned in
https://build.opensuse.org/request/show/1174083 Backports:SLE-12+Backports:SLE-15-SP5 / cacti+cacti-spine
Comment 4 Andreas Stieger 2024-05-15 19:31:30 UTC
done