[ALPINE:CVE-2023-49088] cacti vulnerability

Severity Medium
Affected Packages 15
Fixed Packages 15
CVEs 1

[From CVE-2023-49088] Cacti is an open source operational monitoring and fault management framework. The fix applied for CVE-2023-39515 in version 1.2.25 is incomplete as it enables an adversary to have a victim browser execute malicious code when a victim user hovers their mouse over the malicious data source path in data_debug.php. To perform the cross-site scripting attack, the adversary needs to be an authorized cacti user with the following permissions: General Administration>Sites/Devices/Data. The victim of this attack could be any account with permissions to view http://<HOST>/cacti/data_debug.php. As of time of publication, no complete fix has been included in Cacti.

ID
ALPINE:CVE-2023-49088
Severity
medium
Severity from
CVE-2023-49088
URL
https://security.alpinelinux.org/vuln/CVE-2023-49088
Published
2023-12-22T17:15:08
(9 months ago)
Modified
2023-12-22T17:15:08
(9 months ago)
Rights
Alpine Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge x86_64
Affected pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 x86_64
Affected pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 x86_64
Fixed pkg:apk/alpine/cacti?arch=x86&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge x86
Affected pkg:apk/alpine/cacti?arch=x86&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge x86
Fixed pkg:apk/alpine/cacti?arch=x86&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 x86
Affected pkg:apk/alpine/cacti?arch=x86&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 x86
Fixed pkg:apk/alpine/cacti?arch=s390x&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge s390x
Affected pkg:apk/alpine/cacti?arch=s390x&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge s390x
Fixed pkg:apk/alpine/cacti?arch=s390x&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 s390x
Affected pkg:apk/alpine/cacti?arch=s390x&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 s390x
Fixed pkg:apk/alpine/cacti?arch=riscv64&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge riscv64
Affected pkg:apk/alpine/cacti?arch=riscv64&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge ppc64le
Affected pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 ppc64le
Affected pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 ppc64le
Fixed pkg:apk/alpine/cacti?arch=armv7&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge armv7
Affected pkg:apk/alpine/cacti?arch=armv7&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge armv7
Fixed pkg:apk/alpine/cacti?arch=armv7&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 armv7
Affected pkg:apk/alpine/cacti?arch=armv7&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 armv7
Fixed pkg:apk/alpine/cacti?arch=armhf&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge armhf
Affected pkg:apk/alpine/cacti?arch=armhf&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge armhf
Fixed pkg:apk/alpine/cacti?arch=armhf&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 armhf
Affected pkg:apk/alpine/cacti?arch=armhf&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 armhf
Fixed pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-edge alpine cacti = 1.2.25-r0 alpine-edge aarch64
Affected pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-edge alpine cacti < 1.2.25-r0 alpine-edge aarch64
Fixed pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-3.19 alpine cacti = 1.2.25-r0 alpine-3.19 aarch64
Affected pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-3.19 alpine cacti < 1.2.25-r0 alpine-3.19 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...