MEDIUM
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter
Published Sep 23, 2019
4.3
MEDIUMCVSS 3.1
EPSS 1.23%
Description
In Cacti through 1.2.6, authenticated users may bypass authorization checks (for viewing a graph) via a direct graph_json.php request with a modified local_graph_id parameter.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (10)
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00001.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00005.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00042.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2020-04/msg00048.html vendor-advisoryx_refsource_SUSE
- https://github.com/Cacti/cacti/issues/2964 x_refsource_MISCPatchThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZO3ROHHPKLH2JRW7ES5FYSQTWIPNVLQB/ vendor-advisoryx_refsource_FEDORA
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ZSCUUCKSYVZLN3PQE7NU76AFWUGT3E2D/ vendor-advisoryx_refsource_FEDORA
- https://seclists.org/bugtraq/2020/Jan/25 mailing-listx_refsource_BUGTRAQ
- https://security.gentoo.org/glsa/202003-40 vendor-advisoryx_refsource_GENTOO
- https://www.debian.org/security/2020/dsa-4604 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 23, 2019
Updated Aug 5, 2024
Reserved Sep 23, 2019
Link CVE-2019-16723
CISA Vulnrichment
Updated n/a