REDHAT-BUG-845124: High severity Ganglia Web vulnerability
Upstream has released Ganglia Web 3.5.1 [1] which includes a fix for a security flaw going back to 3.1.7 and possibly earlier versions. This flaw can lead to the arbitrary execution of scripts with the privileges of the web user (apache or nobody), which could possibly lead to other compromises or data exposure. This flaw has been fixed in upstream 3.5.1. No further information is currently available regarding the flaw or a patch.
[1] http://ganglia.info/?p=549
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-845124?
The severity of REDHAT-BUG-845124 is critical due to the potential for arbitrary script execution with web user privileges.
How do I fix REDHAT-BUG-845124?
To fix REDHAT-BUG-845124, update to Ganglia Web version 3.5.1 or later.
Which versions of Ganglia Web are affected by REDHAT-BUG-845124?
REDHAT-BUG-845124 affects Ganglia Web versions from 3.1.7 and possibly earlier.
What are the consequences of not addressing REDHAT-BUG-845124?
Not addressing REDHAT-BUG-845124 may lead to arbitrary script execution, compromising the security of the web server.
Who is the vendor for the affected software in REDHAT-BUG-845124?
The vendor for the affected software in REDHAT-BUG-845124 is Ganglia.