First published: Wed May 20 2020(Updated: )
In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | <1.2.11 | |
Debian Debian Linux | =9.0 | |
Fedoraproject Fedora | =31 | |
Fedoraproject Fedora | =32 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-13230.
CVE-2020-13230 has a severity level of medium.
CVE-2020-13230 affects Cacti versions before 1.2.11, Debian Linux version 9.0, and Fedora versions 31 and 32.
The impact of CVE-2020-13230 is that disabling a user account does not immediately invalidate any permissions granted to that account.
To fix CVE-2020-13230, update to Cacti version 1.2.11 or apply the necessary patches provided by the vendor.