CVE Vulnerabilities

CVE-2020-13230

Improper Preservation of Permissions

Published: May 20, 2020 | Modified: Nov 07, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

In Cacti before 1.2.11, disabling a user account does not immediately invalidate any permissions granted to that account (e.g., permission to view logs).

Weakness

The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.

Affected Software

Name Vendor Start Version End Version
Cacti Cacti * 1.2.11 (excluding)
Cacti Ubuntu bionic *
Cacti Ubuntu eoan *
Cacti Ubuntu esm-apps/bionic *
Cacti Ubuntu esm-apps/focal *
Cacti Ubuntu esm-apps/xenial *
Cacti Ubuntu focal *
Cacti Ubuntu groovy *
Cacti Ubuntu trusty *
Cacti Ubuntu upstream *
Cacti Ubuntu xenial *

References