Your submission was sent successfully! Close

You have successfully unsubscribed! Close

Thank you for signing up for our newsletter!
In these regular emails you will find the latest updates about Ubuntu and upcoming events where you can meet our team.Close

CVE-2019-16723

Published: 23 September 2019

In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.

Notes

AuthorNote
ccdm94
7a6a17252a1 and c7cf4a26e48 were the original fixes proposed for this
CVE, however, they were reverted by cfb0733597a, which introduced a new
fix. This new fix, however, was considered incomplete, so 9a1d2ec46d2,
d5f98679a06 and 4cecb19f6be were issued as follow up patches.

Priority

Medium

Cvss 3 Severity Score

4.3

Score breakdown

Status

Package Release Status
cacti
Launchpad, Ubuntu, Debian
bionic Needed

disco Ignored
(end of life)
eoan Ignored
(end of life)
focal Not vulnerable
(1.2.10+ds1-1ubuntu1)
groovy Ignored
(end of life)
hirsute Not vulnerable
(1.2.16+ds1-2ubuntu1)
impish Not vulnerable
(1.2.16+ds1-2ubuntu1)
jammy Not vulnerable
(1.2.16+ds1-2ubuntu1)
kinetic Not vulnerable
(1.2.16+ds1-2ubuntu1)
lunar Not vulnerable
(1.2.16+ds1-2ubuntu1)
mantic Not vulnerable
(1.2.16+ds1-2ubuntu1)
trusty Needs triage

upstream
Released (1.2.7)
xenial Not vulnerable
(code not present)
Patches:
upstream: https://github.com/Cacti/cacti/commit/cfb0733597af97abc92270de4f47cbfa32f9ce8b
upstream: https://github.com/Cacti/cacti/commit/9a1d2ec46d2dde23826c134ca70a0cd3bef43ee7
upstream: https://github.com/Cacti/cacti/commit/d5f98679a06aa96adfe04f60908f9108cfc9f7f7
upstream: https://github.com/Cacti/cacti/commit/4cecb19f6be8b84fa1c7b6450b66176007cb53df

Severity score breakdown

Parameter Value
Base score 4.3
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality Low
Integrity impact None
Availability impact None
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N