Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ openSUSE-SU-2023:0275-1 — cacti (CVE-2023-30534 +16 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for cacti, cacti-spine

This update for cacti, cacti-spine fixes the following issues:

cacti-spine 1.2.25:

  • Spine should see if script to be executed is executable
  • Enhance number recognition
  • When polling devices, sort by larger number of items first
  • Log format may be corrupted when timeout occurs
  • Compile warning appears due to GCC flag on RHEL7/RHEL8
  • Downed device detection only checks one of the two uptime OIDs
  • Compile error appears due to execinfo.h on FreeBSD
  • Bootstrap shell script contains some PHP cruft
  • Padding is not always removed from the start of non-numeric strings
  • Improve SNMP result handling for non-numeric results
  • Further improve SNMP result handling for non-numeric results
  • Remove check for the max_oids column which has been present since Cacti v1.0
  • Minimize Sorting when fetching poller records for maximum performance
  • Spine should see if script to be executed is executable

cacti-spine 1.2.24:

  • Fix segfault when ignoring older OIDs

cacti 1.2.25:

  • CVE-2023-30534: Protect against Insecure deserialization of filter data (boo#1215082)
  • CVE-2023-39360: Cross-Site Scripting vulnerability when creating new graphs (boo#1215044)
  • CVE-2023-39361: Unauthenticated SQL Injection when viewing graphs (boo#1215045)
  • CVE-2023-39357: SQL Injection when saving data with sql_save() (boo#1215040)
  • CVE-2023-39362: Authenticated command injection when using SNMP options (boo#1215047)
  • CVE-2023-39359: Authenticated SQL injection vulnerability when managing graphs (boo#1215043)
  • CVE-2023-39358: Authenticated SQL injection vulnerability when managing reports (boo#1215042)
  • CVE-2023-39365: SQL Injection when using regular expressions (boo#1215051)
  • CVE-2023-39364: redirect in change password functionality (boo#1215050)
  • CVE-2023-39366: Cross-Site Scripting vulnerability with Device Name when managing Data Sources (boo#1215052)
  • CVE-2023-39510: Cross-Site Scripting vulnerability with Device Name when administrating Reports (boo#1215053)
  • CVE-2023-39511: Cross-Site Scripting vulnerability with Device Name when editing Graphs whilst managing Reports (boo#1215081)
  • CVE-2023-39512: Cross-Site Scripting vulnerability with Device Name when managing Data Sources (boo#1215054)
  • CVE-2023-39513: Cross-Site Scripting vulnerability with Device Name when debugging data queries (boo#1215055)
  • CVE-2023-39514: Cross-Site Scripting vulnerability with Data Source Name when managing Graphs (boo#1215056)
  • CVE-2023-39515: Cross-Site Scripting vulnerability with Data Source Name when debugging Data Queries (boo#1215058)
  • CVE-2023-39516: Cross-Site Scripting vulnerability with Data Source Information when managing Data Sources (boo#1215059)
  • When rebuilding the Poller Cache from command line, allow it to be multi-threaded
  • When searching tree or list views, the URL does not update after changes
  • When creating a Data Source Template with a specific snmp port, the port is not always applied
  • When a Data Query references a file, the filename should be trimmed to remove spurious spaces
  • THold plugin may not always install or upgrade properly
  • RRD file structures are not always updated properly, if there are more Data Sources in the Data Template than the Graph Template
  • When reindexing devices, errors may sometimes be shown
  • Boost may loose data when the database server is overloaded
  • Boost can sometimes output unexpected or invalid values
  • Boost should not attempt to start if there are no items to process
  • Rebuilding the poller cache does not always work as expected
  • Host CPU items may not work poll as expected when on a remote data collector where hmib is also enabled
  • When creating new graphs, invalid offset errors may be generated
  • When importing packages, SQL errors may be generated
  • When managing plugins from command line, the --plugin option is not properly handled
  • When automating an install of Cacti, error messages can be appear
  • When performing automated install of a plugin, warnings can be thrown
  • Automation references the wrong table name causing errors
  • Data Source Info Mode produces invalid recommendations
  • Data Source Debug 'Run All' generates too many log messages
  • The description of rebuild poller cache in utilities does not display properly
  • When reindexing a device, debug information may not always display properly
  • Upon displaying a form with errors, the session error fields variable isn't cleared
  • MariaDB clusters will no longer support exclusive locks
  • RRDtool can fail to update when sources in Data Template and Graph Template data sources do not match
  • Compatibility improvements for Boost under PHP 8.x
  • When searching the tree, increase the time before querying for items
  • Device Location drop down does not always populate correctly
  • When viewing Realtime graphs, undefined variable errors may be reported
  • SNMP Uptime is not always ignored for spikekills
  • Improve detection of downed Devices
  • When reporting missing functions from Pl

Affected software

openSUSE-SU-2023:0275-1 is recorded against 2 packages.

  • cacti (fixed in 1.2.25-bp155.2.3.1)
  • cacti-spine (fixed in 1.2.25-bp155.2.3.1)

Timeline and source

Published on 26 September 2023 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-09-26
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
cacti 1.2.25-bp155.2.3.1
cacti-spine 1.2.25-bp155.2.3.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by openSUSE-SU-2023:0275-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2023:0275-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.