Hugo Lefeuvre pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
36092749 by Hugo Lefeuvre at 2020-01-12T16:45:05+01:00
CVE-2019-16723/cacti: add followup patches
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -23029,6 +23029,9 @@ CVE-2019-16723 (In Cacti through 1.2.6, authenticated
users may bypass authoriza
NOTE:
https://github.com/Cacti/cacti/commit/c7cf4a26e4848872b48094e67f8d0a01dd7613d2
NOTE: after further discussion, upstream issued a new fix which reverts
previous commits
NOTE:
https://github.com/Cacti/cacti/commit/cfb0733597af97abc92270de4f47cbfa32f9ce8b
+ NOTE: which turned out to be insufficient to fix the issue, follow up
patches:
+ NOTE:
https://github.com/Cacti/cacti/commit/9a1d2ec46d2dde23826c134ca70a0cd3bef43ee7
+ NOTE:
https://github.com/Cacti/cacti/commit/d5f98679a06aa96adfe04f60908f9108cfc9f7f7
NOTE: The original issue mentions only a bypass via graph_json.php but
there are
NOTE: additional permission checks missed while checking the issue
fixed with the
NOTE: upstream commits.
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/360927495dda095e9e008798031b453409ac908b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/commit/360927495dda095e9e008798031b453409ac908b
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits