Improper Input Validation Affecting cacti package, versions <0:1.1.19-4.22.amzn1


Severity

Recommended
0.0
high
0
10

Based on Amazon Linux security rating.

Threat Intelligence

EPSS
0.35% (72nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Improper Input Validation vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-AMZN201803-CACTI-5928995
  • published4 Oct 2023
  • disclosed5 Sept 2023

Introduced: 5 Sep 2023

CVE-2023-39357  (opens in a new tab)
CWE-20  (opens in a new tab)
CWE-89  (opens in a new tab)

How to fix?

Upgrade Amazon-Linux:2018.03 cacti to version 0:1.1.19-4.22.amzn1 or higher.
This issue was patched in ALAS-2023-1842.

NVD Description

Note: Versions mentioned in the description apply only to the upstream cacti package and not the cacti package as distributed by Amazon-Linux. See How to fix? for Amazon-Linux:2018.03 relevant fixed versions and status.

Cacti is an open source operational monitoring and fault management framework. A defect in the sql_save function was discovered. When the column type is numeric, the sql_save function directly utilizes user input. Many files and functions calling the sql_save function do not perform prior validation of user input, leading to the existence of multiple SQL injection vulnerabilities in Cacti. This allows authenticated users to exploit these SQL injection vulnerabilities to perform privilege escalation and remote code execution. This issue has been addressed in version 1.2.25. Users are advised to upgrade. There are no known workarounds for this vulnerability.

CVSS Scores

version 3.1