CVE-2019-17357

NameCVE-2019-17357
DescriptionCacti through 1.2.7 is affected by a graphs.php?template_id= SQL injection vulnerability affecting how template identifiers are handled when a string and id composite value are used to identify the template type and id. An authenticated attacker can exploit this to extract data from the database, or an unauthenticated remote attacker could exploit this via Cross-Site Request Forgery.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, Mageia, GitHub advisories/code/issues, web search, more)
Debian Bugs947374

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
cacti (PTS)buster1.2.2+ds1-2+deb10u4fixed
buster (security)1.2.2+ds1-2+deb10u2fixed
bullseye1.2.16+ds1-2fixed
bookworm1.2.22+ds1-2fixed
sid1.2.22+ds1-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
cactisourcejessie(not affected)
cactisourcestretch(not affected)
cactisourcebuster1.2.2+ds1-2+deb10u2
cactisource(unstable)1.2.8+ds1-1947374

Notes

[stretch] - cacti <not-affected> (Vulnerable code not present)
[jessie] - cacti <not-affected> (Vulnerable code not present)
https://github.com/Cacti/cacti/issues/3025
https://github.com/Cacti/cacti/commit/d6dc48503bbcde0717e7a93df7638fd4796200f4

Search for package or bug name: Reporting problems