There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.
References
Link | Resource |
---|---|
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: INCIBE
Published: 2023-01-27T00:00:00
Updated: 2023-01-27T00:00:00
Reserved: 2022-10-28T00:00:00
Link: CVE-2022-43978
JSON object: View
NVD Information
Status : Analyzed
Published: 2023-01-27T22:15:08.533
Modified: 2023-06-27T02:44:47.710
Link: CVE-2022-43978
JSON object: View
Redhat Information
No data.