{"schema_version":"1.7.3","id":"openSUSE-SU-2020:0284-1","published":"2020-03-02T12:20:59Z","modified":"2026-02-04T02:20:34.781286Z","related":["CVE-2009-4112","CVE-2018-20723","CVE-2018-20724","CVE-2018-20725","CVE-2018-20726","CVE-2019-16723","CVE-2019-17357","CVE-2019-17358","CVE-2020-7106","CVE-2020-7237"],"upstream":["CVE-2009-4112","CVE-2018-20723","CVE-2018-20724","CVE-2018-20725","CVE-2018-20726","CVE-2019-16723","CVE-2019-17357","CVE-2019-17358","CVE-2020-7106","CVE-2020-7237"],"summary":"Security update for cacti, cacti-spine","details":"This update for cacti, cacti-spine fixes the following issues:\n\ncacti-spine was updated to version 1.2.9.\n\n\nSecurity issues fixed:\n\n- CVE-2009-4112: Fixed a privilege escalation (bsc#1122535).\n- CVE-2018-20723: Fixed a cross-site scripting (XSS) vulnerability (bsc#1122245).\n- CVE-2018-20724: Fixed a cross-site scripting (XSS) vulnerability (bsc#1122244).\n- CVE-2018-20725: Fixed a privilege escalation that could occur under certain conditions (bsc#1122535).\n- CVE-2018-20726: Fixed a cross-site scripting (XSS) vulnerability (bsc#1122242).\n- CVE-2019-16723: Fixed an authentication bypass vulnerability.\n- CVE-2019-17357: Fixed an SQL injection vulnerability (bsc#1158990).\n- CVE-2019-17358: Fixed an unsafe deserialization in sanitize_unserialize_selected_items (bsc#1158992).\n- CVE-2020-7106: Fixed a potential cross-site scripting (XSS) vulnerability (bsc#1163749).\n- CVE-2020-7237: Fixed a remote code execution that affected privileged users via shell metacharacters in the Performance Boost Debug Log field (bsc#1161297).\n\n\nNon-security issues fixed:\n\n- Fixed missing packages php-json, php-ctype, and php-gd in cacti.spec (boo#1101024).\n- Fixed Apache2.4 and Apache2.2 runtime configuration issue (boo#1101139).\n\nThis update was imported from the openSUSE:Leap:15.1:Update update project.","affected":[{"package":{"name":"cacti","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9-bp151.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"cacti":"1.2.9-bp151.4.3.1","cacti-spine":"1.2.9-bp151.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0284-1.json"}},{"package":{"name":"cacti-spine","ecosystem":"SUSE:Package Hub 15 SP1","purl":"pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP1"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.9-bp151.4.3.1"}]}],"ecosystem_specific":{"binaries":[{"cacti":"1.2.9-bp151.4.3.1","cacti-spine":"1.2.9-bp151.4.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2020:0284-1.json"}}],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/E42YKBXB3DG7EDJCOOGLDZ757NRYDL6I/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1082318"},{"type":"REPORT","url":"https://bugzilla.suse.com/1101024"},{"type":"REPORT","url":"https://bugzilla.suse.com/1101139"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122242"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122243"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122244"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122245"},{"type":"REPORT","url":"https://bugzilla.suse.com/1122535"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158990"},{"type":"REPORT","url":"https://bugzilla.suse.com/1158992"},{"type":"REPORT","url":"https://bugzilla.suse.com/1161297"},{"type":"REPORT","url":"https://bugzilla.suse.com/1163749"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2009-4112"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20723"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20724"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20725"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2018-20726"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-16723"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17357"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2019-17358"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-7106"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-7237"}]}