File _patchinfo of Package patchinfo.12422

<patchinfo incident="12422">
  <issue tracker="fate" id="326485"/>
  <issue tracker="bnc" id="1122535">VUL-1: CVE-2009-4112: cacti: Privilege escalation under certain conditions</issue>
  <issue tracker="bnc" id="1169215">VUL-0: cacti: multiple vulnerabilities fixed and security hardening applied in 1.2.11</issue>
  <issue tracker="bnc" id="1158992">VUL-0: CVE-2019-17358: cacti: Unsafe deserialization in sanitize_unserialize_selected_items</issue>
  <issue tracker="bnc" id="1164675">VUL-0: CVE-2020-8813: cacti: remote attackers may execute arbitrary OS commands via shell metacharacters in a cookie, if a guest user has the graph real-time privilege</issue>
  <issue tracker="bnc" id="1122244">VUL-1: CVE-2018-20724: cacti: cross-site scripting (XSS) vulnerability exists in pollers.php due to lack of escaping of unintended characters in the Website Hostname for Data Collectors.</issue>
  <issue tracker="bnc" id="1122242">VUL-1: CVE-2018-20726: cacti: cross-site scripting (XSS) vulnerability exists in host.php (via tree.php) in Cacti in the Website Hostname field for Devices.</issue>
  <issue tracker="bnc" id="1122243">VUL-1: CVE-2018-20725: cacti: cross-site scripting (XSS) vulnerability exists in graph_templates.php due to lack of escaping of unintended characters in the Graph Vertical Label.</issue>
  <issue tracker="bnc" id="1161297">VUL-0: CVE-2020-7237: cacti: Remote Code Execution (by privileged users) via shell metacharacters in the Performance Boost Debug Log field of poller_automation.php</issue>
  <issue tracker="bnc" id="1122245">VUL-1: CVE-2018-20723: cacti: cross-site scripting (XSS) vulnerability exists in color_templates.php due to lack of escaping of unintended characters in the Name field for a Color.</issue>
  <issue tracker="bnc" id="1082318">Packages must not mark license files as %doc</issue>
  <issue tracker="bnc" id="1158990">VUL-0: CVE-2019-17357: cacti: sql injection in graphs.php</issue>
  <issue tracker="cve" id="2018-20724"/>
  <issue tracker="cve" id="2018-20726"/>
  <issue tracker="cve" id="2018-20725"/>
  <issue tracker="cve" id="2020-7106"/>
  <issue tracker="cve" id="2009-4112"/>
  <issue tracker="cve" id="2019-17358"/>
  <issue tracker="cve" id="2020-7237"/>
  <issue tracker="cve" id="2020-8813"/>
  <issue tracker="cve" id="2019-16723"/>
  <issue tracker="cve" id="2019-17357"/>
  <issue tracker="cve" id="2018-20723"/>
  <packager>AndreasStieger</packager>
  <rating>important</rating>
  <category>security</category>
  <summary>Security update for cacti, cacti-spine</summary>
  <description>This update for cacti, cacti-spine to version 1.2.11 fixes the following issues:

This update is fixing multiple vulnerabilities and adding bug fixes. For more details consult the changes file.
</description>
</patchinfo>
openSUSE Build Service is sponsored by