The following table lists the changes that have been made to the
CVE-2024-45598 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution
of a vulnerability, and for identifying the most recent changes that may
impact the vulnerability’s severity, exploitability, or other characteristics.
-
New CVE Received
by [email protected]Jan. 27, 2025
Action Type Old Value New Value Added Description Cacti is an open source performance and fault management framework. Prior to 1.2.29, an administrator can change the `Poller Standard Error Log Path` parameter in either Installation Step 5 or in Configuration->Settings->Paths tab to a local file inside the server. Then simply going to Logs tab and selecting the name of the local file will show its content on the web UI. This vulnerability is fixed in 1.2.29. Added CVSS V3.1 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:L Added CWE CWE-22 Added Reference https://github.com/Cacti/cacti/commit/eca52c6bb3e76c55d66b1040baa6dbf37471a0ae Added Reference https://github.com/Cacti/cacti/security/advisories/GHSA-pv2c-97pp-vxwg