First published: Thu Mar 03 2022(Updated: )
Under certain ldap conditions, Cacti authentication can be bypassed with certain credential types.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cacti Cacti | =1.2.19 | |
Debian Debian Linux | =9.0 | |
Debian Debian Linux | =10.0 | |
Debian Debian Linux | =11.0 | |
Fedoraproject Fedora | =34 | |
Fedoraproject Fedora | =35 | |
Fedoraproject Fedora | =36 | |
debian/cacti | <=1.2.2+ds1-2+deb10u4 | 1.2.2+ds1-2+deb10u5 1.2.16+ds1-2+deb11u1 1.2.24+ds1-1 1.2.25+ds1-2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0730 is a vulnerability in Cacti that allows bypassing authentication under certain LDAP conditions.
CVE-2022-0730 affects Cacti version 1.2.19.
CVE-2022-0730 affects Debian Linux versions 9.0, 10.0, and 11.0.
CVE-2022-0730 has a severity rating of critical (9.8).
To fix CVE-2022-0730 in Cacti, update to version 1.2.25+ds1-2 or a later version.
To fix CVE-2022-0730 in Debian Linux, apply the appropriate updates: 1.2.2+ds1-2+deb10u5, 1.2.16+ds1-2+deb11u1, 1.2.24+ds1-1, or 1.2.25+ds1-2.
CVE-2022-0730 is classified as CWE-287.