Cron log backup files contain administrator session IDs....
High severity
Unreviewed
Published
Nov 23, 2023
to the GitHub Advisory Database
•
Updated Nov 30, 2023
Description
Published by the National Vulnerability Database
Nov 23, 2023
Published to the GitHub Advisory Database
Nov 23, 2023
Last updated
Nov 30, 2023
Cron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs directory for cron log backups. The contents of these log files can then be abused to authenticate to the application as an administrator. This issue affects Pandora FMS <= 772.
References