[Git][security-tracker-team/security-tracker][master] CVE-2019-16723/cacti: one more followup patch...
Hugo Lefeuvre
hle at debian.org
Sun Jan 12 15:55:36 GMT 2020
Hugo Lefeuvre pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5a517b60 by Hugo Lefeuvre at 2020-01-12T16:55:10+01:00
CVE-2019-16723/cacti: one more followup patch...
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -23032,6 +23032,7 @@ CVE-2019-16723 (In Cacti through 1.2.6, authenticated users may bypass authoriza
NOTE: which turned out to be insufficient to fix the issue, follow up patches:
NOTE: https://github.com/Cacti/cacti/commit/9a1d2ec46d2dde23826c134ca70a0cd3bef43ee7
NOTE: https://github.com/Cacti/cacti/commit/d5f98679a06aa96adfe04f60908f9108cfc9f7f7
+ NOTE: https://github.com/Cacti/cacti/commit/4cecb19f6be8b84fa1c7b6450b66176007cb53df
NOTE: The original issue mentions only a bypass via graph_json.php but there are
NOTE: additional permission checks missed while checking the issue fixed with the
NOTE: upstream commits.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5a517b60775a2d5c3fa1d3b15f24151ec411d32b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/5a517b60775a2d5c3fa1d3b15f24151ec411d32b
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20200112/e38c7c13/attachment-0001.html>
More information about the debian-security-tracker-commits
mailing list