FlawAtlas
Search the atlas
OPENSUSE-SU-2020:0654-1 Not scored

Security update for cacti, cacti-spine

This update for cacti, cacti-spine fixes the following issues: cacti-spine and cacti were updated to 1.2.12: cacti fixes: * CVE-2020-7106: Lack of escaping of color items can lead to XSS exposure (boo#1163749) * Fix multiple graphing bugs and web UI issues * Fix multiple warnings, PHP Exceptions and errors * Content-Security-Policy prevents External Links from being opened * Prevent runtime memory issues by increasing memory limit * Improve SNMPv3 handling cacti-spine fixes: * Failed host lookup causes spine to crash

Exploit probability Not scored
Published May 11, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Package Hub 12 cacti
SUSE:Package Hub 12 cacti-spine
SUSE:Package Hub 15 SP1 cacti
SUSE:Package Hub 15 SP1 cacti-spine
openSUSE:Leap 15.1 cacti
openSUSE:Leap 15.1 cacti-spine

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities openSUSE-SU-2020:0654-1

This update for cacti, cacti-spine fixes the following issues: cacti-spine and cacti were updated to 1.2.12: cacti fixes: * CVE-2020-7106: Lack of escaping of color items can lead to XSS exposure (boo#1163749) * Fix multiple graphing bugs and web UI issues * Fix multiple warnings, PHP Exceptions and errors * Content-Security-Policy prevents External Links from being opened * Prevent runtime memory issues by increasing memory limit * Improve SNMPv3 handling cacti-spine fixes: * Failed host lookup causes spine to crash

View original source

05 / REFERENCES

Further evidence