Improper Preservation of Permissions in Cacti - CVE-2020-13230
Published: July 26, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to otherwise restricted functionality.
The vulnerability exists due to application does not properly processes operations, related to accounts deactivation. When disabling a user account the application does not immediately invalidate any permissions
granted to that account (e.g., permission to view logs). A remote attacker, whose account was disabled can still access the application for certain amount of time.
Affected software
Fedora
cacti
cacti-spine
How to mitigate CVE-2020-13230
cacti - addressed in versions 1.2.12-1.el7, 1.2.12-1.el8, 1.2.12-1.fc31, 1.2.12-1.fc32
cacti-spine - addressed in versions 1.2.12-1.el7, 1.2.12-1.el8, 1.2.12-1.fc31, 1.2.12-1.fc32
External References
- https://github.com/Cacti/cacti/issues/3343
- https://github.com/Cacti/cacti/releases/tag/release%2F1.2.11
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ICJMWSY77IIGZYR6FE6NAQZFBO42VECO/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q3PCDGNELH7HEBIXRNT5J5EWQEXQAU6B/