漏洞描述
Cacti through 1.2.22 is susceptible to remote command injection. There is insufficient authorization within the remote agent when handling HTTP requests with a custom Forwarded-For HTTP header. An attacker can send a specially crafted HTTP request to the affected instance and execute arbitrary OS commands on the server, thereby making it possible to obtain sensitive information, modify data, and/or execute unauthorized administrative operations in the context of the affected site.
影响产品
修复建议
建议关注厂商安全公告,及时升级至已修复版本,并结合实际资产暴露情况采取缓解措施。
参考链接
security-tracker.debian.orghttps://security-tracker.debian.org/tracker/CVE-2022-46169↗github.comhttps://github.com/Cacti/cacti/security/advisories/GHSA-6p93-p743-35gf↗www.cybersecurity-help.czhttps://www.cybersecurity-help.cz/vdb/SB2022121926↗nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2022-46169↗github.comhttps://github.com/Cacti/cacti/commit/7f0e16312dd5ce20f93744ef8b9c3b0f1ece2216↗