Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: PandoraFMS

Published: 2023-11-23T14:22:01.559Z

Updated: 2023-11-23T14:22:01.559Z

Reserved: 2023-08-31T15:38:14.018Z


Link: CVE-2023-4677

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-11-23T15:15:10.410

Modified: 2023-11-30T17:06:24.530


Link: CVE-2023-4677

JSON object: View

cve-icon Redhat Information

No data.