CVE-2014-2327
published 2014-04-23CVE-2014-2327: Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for…
PriorityP431medium6.8CVSS 2.0
AVNACMAuNCPIPAP
EPSS
2.30%
81.5th percentile
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cacti | cacti | >= 0 < 0.8.8b+dfsg-6 | 0.8.8b+dfsg-6 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-6 | 0.8.8b+dfsg-6 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-6 | 0.8.8b+dfsg-6 |
| cacti | cacti | >= 0 < 0.8.8b+dfsg-6 | 0.8.8b+dfsg-6 |
| cacti | cacti | 0.8.7 – 0.8.7g | — |
| cacti | cacti | 0.8.8 – 0.8.8b | — |
| debian | cacti | < cacti 0.8.8b+dfsg-6 (bookworm) | cacti 0.8.8b+dfsg-6 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv6.8MEDIUM
vendor_debian6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w6fq-c949-4cc3: Cross-site request forgery (CSRF) vulnerability in Cacti 0
ghsa_unreviewed·2022-05-14
CVE-2014-2327 [MEDIUM] CWE-352 GHSA-w6fq-c949-4cc3: Cross-site request forgery (CSRF) vulnerability in Cacti 0
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
OSV
CVE-2014-2327: Cross-site request forgery (CSRF) vulnerability in Cacti 0
osv·2014-04-23·CVSS 6.8
CVE-2014-2327 [MEDIUM] CVE-2014-2327: Cross-site request forgery (CSRF) vulnerability in Cacti 0
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
Debian
CVE-2014-2327: cacti - Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and ear...
vendor_debian·2014·CVSS 6.8
CVE-2014-2327 [MEDIUM] CVE-2014-2327: cacti - Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and ear...
Cross-site request forgery (CSRF) vulnerability in Cacti 0.8.7g, 0.8.8b, and earlier allows remote attackers to hijack the authentication of users for unspecified commands, as demonstrated by requests that (1) modify binary files, (2) modify configurations, or (3) add arbitrary users.
Scope: local
bookworm: resolved (fixed in 0.8.8b+dfsg-6)
bullseye: resolved (fixed in 0.8.8b+dfsg-6)
forky: resolved (fixed in 0.8.8b+dfsg-6)
sid: resolved (fixed in 0.8.8b+dfsg-6)
trixie: resolved (fixed in 0.8.8b+dfsg-6)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)
bugzilla·2015-11-25·CVSS 7.5
CVE-2015-2327 [HIGH] CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)
CVE-2015-2327 pcre: infinite recursion compiling pattern with zero-repeated groups that include recursive back reference (8.36/19)
A stack-based buffer overflow vulnerability was found in compile_regex(), triggered via crafted regular expression.
Upstream bug (contains reproducer):
https://bugs.exim.org/show_bug.cgi?id=1503
Upstream patch:
http://vcs.pcre.org/pcre?view=revision&revision=1495
CVE request:
http://www.openwall.com/lists/oss-security/2015/05/31/5
Discussion:
Created pcre tracking bugs for this issue:
Affects: fedora-all [bug 1285409]
---
Upstream fixed it in 8.36 version. A reproducer is crash when compiling /(((a\2)|(a*)\g))*a?/BZ expression in pcretest tool.
---
This was fixed with pcre-8.35-4.fc21 in Fedora on 2014-07-14. No supported Fedora is affected now.
Bugzilla
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]
bugzilla·2014-04-01·CVSS 4.3
CVE-2014-2327 [MEDIUM] CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Bugzilla
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]
bugzilla·2014-04-01·CVSS 4.3
CVE-2014-2327 [MEDIUM] CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]
CVE-2014-2327 CVE-2014-2326 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availabl
Bugzilla
CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom
bugzilla·2014-03-28·CVSS 4.3
CVE-2014-2326 [MEDIUM] CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom
CVE-2014-2326 CVE-2014-2327 CVE-2014-2328 cacti: multiple flaws reported by Deutsche Telekom
A posting to bugtraq from Deutsche Telekom [1] noted multiple flaws in Cacti 0.8.7g:
CVE-2014-2326: stored XSS
"The Cacti application is susceptible to stored XSS attacks. This is mainly the result of improper output encoding."
CVE-2014-2327: missing CSRF token
"The Cacti application does not implement any CSRF tokens. More about CSRF attacks, risks and mitigations see https://www.owasp.org/index.php/Cross-Site_Request_Forgery_(CSRF). This attack has a vast impact on the security of the Cacti application, as multiple configuration parameters can be changed using a CSRF attack. One very critical attack vector is the modification of several binary files in the Cacti configuration, which may then b
http://jvn.jp/en/jp/JVN55076671/index.htmlhttp://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002239.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00034.htmlhttp://secunia.com/advisories/59203http://www.debian.org/security/2014/dsa-2970http://www.securityfocus.com/archive/1/531588http://www.securityfocus.com/bid/66392https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768https://security.gentoo.org/glsa/201509-03http://jvn.jp/en/jp/JVN55076671/index.htmlhttp://jvndb.jvn.jp/ja/contents/2014/JVNDB-2014-002239.htmlhttp://lists.opensuse.org/opensuse-updates/2015-03/msg00034.htmlhttp://secunia.com/advisories/59203http://www.debian.org/security/2014/dsa-2970http://www.securityfocus.com/archive/1/531588http://www.securityfocus.com/bid/66392https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=742768https://security.gentoo.org/glsa/201509-03
2014-04-23
Published