CVE-2023-39361
Publication date 5 September 2023
Last updated 24 July 2024
Ubuntu priority
Cvss 3 Severity Score
Cacti is an open source operational monitoring and fault management framework. Affected versions are subject to a SQL injection discovered in graph_view.php. Since guest users can access graph_view.php without authentication by default, if guest users are being utilized in an enabled state, there could be the potential for significant damage. Attackers may exploit this vulnerability, and there may be possibilities for actions such as the usurpation of administrative privileges or remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Read the notes from the security team
Why is this CVE high priority?
The vulnerable page can be accessed without authentication by default and the vulnerability can be exploited remotely and lead to code execution.
Status
Package | Ubuntu Release | Status |
---|---|---|
cacti | 24.04 LTS noble |
Fixed 1.2.25+ds1-2
|
22.04 LTS jammy |
Fixed 1.2.19+ds1-2ubuntu1+esm1
|
|
20.04 LTS focal |
Not affected
|
|
18.04 LTS bionic |
Not affected
|
|
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
Get expanded security coverage with Ubuntu Pro
Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.
Get Ubuntu ProNotes
alexmurray
This was introduced upstream via https://github.com/Cacti/cacti/commit/36269461cb9b03581ad5d7f6ddbc085a28fb9c37 and so only 1.2.19 and later were affected.
Severity score breakdown
Parameter | Value |
---|---|
Base score | 9.8 · Critical |
Attack vector | Network |
Attack complexity | Low |
Privileges required | None |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
References
Related Ubuntu Security Notices (USN)
- USN-6720-1
- Cacti vulnerability
- 2 April 2024