Input validation error in Cacti - CVE-2020-7237
Published: January 20, 2020 / Updated: May 19, 2022
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insufficient validation of user-supplied input in the Performance Boost Debug Log field of "poller_automation.php". A remote authenticated attacker can execute arbitrary code via shell metacharacters.
Affected software
Gentoo Linux
Fedora
SUSE Linux
Opensuse
cacti (Alpine package)
cacti
cacti-spine
SUSE Package Hub for SUSE Linux Enterprise
How to mitigate CVE-2020-7237
cacti - addressed in versions 1.2.9-1.el7, 1.2.9-1.el8, 1.2.9-1.fc30, 1.2.9-1.fc31
cacti-spine - addressed in versions 1.2.9-1.el7, 1.2.9-1.el8, 1.2.9-1.fc30, 1.2.9-1.fc31
External References
Related Security Bulletins
- Multiple vulnerabilities in Cacti
- Gentoo update for Cacti
- Input validation error in cacti (Alpine package)
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- OpenSUSE Linux update for cacti, cacti-spine
- Fedora 31 update for cacti, cacti-spine
- Fedora 30 update for cacti, cacti-spine
- Fedora EPEL 7 update for cacti, cacti-spine
- Fedora EPEL 8 update for cacti, cacti-spine