{"id":"openSUSE-SU-2021:0787-1","summary":"Security update for cacti, cacti-spine","details":"This update for cacti, cacti-spine fixes the following issues:\n\ncacti-spine was updated to 1.2.17:\n\n* Avoid triggering DDos detection in firewalls on large systems\n* Use mysql reconnect option properly\n* Fix possible creashes in various operations\n* Fix remote data collectors pushing too much data to main when\n  performing diagnostics\n* Make spine more responsive when remote connection is down\n* Fix various MySQL issues\n* Make spine immune to DST changes\n\ncacti-spine 1.2.16:\n\n* Some developer debug log messages falsely labeled as WARNINGS\n* Remove the need of the dos2unix program\n* Fix Spine experiencing MySQL socket error 2002 under load\n* Under heavy load MySQL/MariaDB return 2006 and 2013 errors on query\n* Add backtrace output to stderr for signals\n* Add Data Source turnaround time to debug output\n\ncacti-spine 1.2.15:\n\n* Special characters may not always be ignored properly\n\n\ncacti was updated to 1.2.17:\n\n* Fix incorrect handling of fields led to potential XSS issues\n* CVE-2020-35701: Fix SQL Injection vulnerability (boo#1180804)\n* Fix various XSS issues with HTML Forms handling\n* Fix handling of Daylight Saving Time changes\n* Multiple fixes and extensions to plugins\n* Fix multiple display, export, and input validation issues\n* SNMPv3 Password field was not correctly limited\n* Improved regular expression handling for searcu\n* Improved support for RRDproxy\n* Improved behavior on large systems\n* MariaDB/MysQL: Support persistent connections and improve\n  multiple operations and options\n* Add Theme 'Midwinter'\n* Modify automation to test for data before creating graphs\n* Add hooks for plugins to show customize graph source and customize\n  template url\n* Allow CSRF security key to be refreshed at command line\n* Allow remote pollers statistics to be cleared\n* Allow user to be automatically logged out after admin defined\n  period\n* When replicating, ensure Cacti can detect and verify replica\n  servers\n\n\nThis update was imported from the openSUSE:Leap:15.2:Update update project.","modified":"2026-03-11T07:33:02.759727Z","published":"2021-05-24T04:08:42Z","related":["CVE-2020-35701"],"upstream":["CVE-2020-35701"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/A64OCZCS4IECM2D3DOPFLCT3NC7UHBH7/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1180804"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-35701"}],"affected":[{"package":{"name":"cacti","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/cacti&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-bp152.2.10.1"}]}],"ecosystem_specific":{"binaries":[{"cacti-spine":"1.2.17-bp152.2.7.1","cacti":"1.2.17-bp152.2.10.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0787-1.json"}},{"package":{"name":"cacti-spine","ecosystem":"SUSE:Package Hub 15 SP2","purl":"pkg:rpm/suse/cacti-spine&distro=SUSE%20Package%20Hub%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.2.17-bp152.2.7.1"}]}],"ecosystem_specific":{"binaries":[{"cacti":"1.2.17-bp152.2.10.1","cacti-spine":"1.2.17-bp152.2.7.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2021:0787-1.json"}}],"schema_version":"1.7.5"}