[ALPINE:CVE-2024-31459] cacti vulnerability

Severity High
Affected Packages 15
Fixed Packages 15
CVEs 1

[From CVE-2024-31459] Cacti provides an operational monitoring and fault management framework. Prior to version 1.2.27, there is a file inclusion issue in the lib/plugin.php file. Combined with SQL injection vulnerabilities, remote code execution can be implemented. There is a file inclusion issue with the api_plugin_hook() function in the lib/plugin.php file, which reads the plugin_hooks and plugin_config tables in database. The read data is directly used to concatenate the file path which is used for file inclusion. Version 1.2.27 contains a patch for the issue.

ID
ALPINE:CVE-2024-31459
Severity
high
Severity from
CVE-2024-31459
URL
https://security.alpinelinux.org/vuln/CVE-2024-31459
Published
2024-05-14T15:25:26
(4 months ago)
Modified
2024-05-14T15:25:26
(4 months ago)
Rights
Alpine Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Fixed pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge x86_64
Affected pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge x86_64
Fixed pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 x86_64
Affected pkg:apk/alpine/cacti?arch=x86_64&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 x86_64
Fixed pkg:apk/alpine/cacti?arch=x86&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge x86
Affected pkg:apk/alpine/cacti?arch=x86&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge x86
Fixed pkg:apk/alpine/cacti?arch=x86&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 x86
Affected pkg:apk/alpine/cacti?arch=x86&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 x86
Fixed pkg:apk/alpine/cacti?arch=s390x&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge s390x
Affected pkg:apk/alpine/cacti?arch=s390x&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge s390x
Fixed pkg:apk/alpine/cacti?arch=s390x&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 s390x
Affected pkg:apk/alpine/cacti?arch=s390x&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 s390x
Fixed pkg:apk/alpine/cacti?arch=riscv64&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge riscv64
Affected pkg:apk/alpine/cacti?arch=riscv64&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge riscv64
Fixed pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge ppc64le
Affected pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge ppc64le
Fixed pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 ppc64le
Affected pkg:apk/alpine/cacti?arch=ppc64le&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 ppc64le
Fixed pkg:apk/alpine/cacti?arch=armv7&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge armv7
Affected pkg:apk/alpine/cacti?arch=armv7&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge armv7
Fixed pkg:apk/alpine/cacti?arch=armv7&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 armv7
Affected pkg:apk/alpine/cacti?arch=armv7&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 armv7
Fixed pkg:apk/alpine/cacti?arch=armhf&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge armhf
Affected pkg:apk/alpine/cacti?arch=armhf&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge armhf
Fixed pkg:apk/alpine/cacti?arch=armhf&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 armhf
Affected pkg:apk/alpine/cacti?arch=armhf&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 armhf
Fixed pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-edge alpine cacti = 1.2.27-r0 alpine-edge aarch64
Affected pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-edge alpine cacti < 1.2.27-r0 alpine-edge aarch64
Fixed pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-3.19 alpine cacti = 1.2.27-r0 alpine-3.19 aarch64
Affected pkg:apk/alpine/cacti?arch=aarch64&distro=alpine-3.19 alpine cacti < 1.2.27-r0 alpine-3.19 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...