Skip to content

Missing Authentication for Critical Function in LibreNMS

Moderate severity GitHub Reviewed Published Oct 11, 2019 to the GitHub Advisory Database • Updated Feb 1, 2023

Package

composer librenms/librenms (Composer)

Affected versions

< 1.50.1

Patched versions

1.50.1

Description

An issue was discovered in LibreNMS through 1.47. A number of scripts import the Authentication libraries, but do not enforce an actual authentication check. Several of these scripts disclose information or expose functions that are of a sensitive nature and are not expected to be publicly accessible.

References

Published by the National Vulnerability Database Sep 9, 2019
Reviewed Sep 25, 2019
Published to the GitHub Advisory Database Oct 11, 2019
Last updated Feb 1, 2023

Severity

Moderate

EPSS score

0.414%
(75th percentile)

Weaknesses

CVE ID

CVE-2019-10668

GHSA ID

GHSA-277v-gwfr-hmpj

Source code

No known source code
Loading Checking history
See something to contribute? Suggest improvements for this vulnerability.