Vulnerability Description
An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'" instead of "'middleware' => ['can:admin']" in routes/web.php.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Librenms | Librenms | < 1.65.1 |
References
- https://community.librenms.org/c/announcementsRelease NotesVendor Advisory
- https://github.com/librenms/librenms/commit/e5bb6d80bc308fc56b9a01ffb76c34159995PatchThird Party Advisory
- https://github.com/librenms/librenms/compare/1.65...1.65.1Third Party Advisory
- https://github.com/librenms/librenms/pull/11915PatchThird Party Advisory
- https://github.com/librenms/librenms/releases/tag/1.65.1Release NotesThird Party Advisory
- https://shielder.it/blogExploitThird Party Advisory
- https://community.librenms.org/c/announcementsRelease NotesVendor Advisory
- https://github.com/librenms/librenms/commit/e5bb6d80bc308fc56b9a01ffb76c34159995PatchThird Party Advisory
- https://github.com/librenms/librenms/compare/1.65...1.65.1Third Party Advisory
- https://github.com/librenms/librenms/pull/11915PatchThird Party Advisory
- https://github.com/librenms/librenms/releases/tag/1.65.1Release NotesThird Party Advisory
- https://shielder.it/blogExploitThird Party Advisory
FAQ
What is CVE-2020-15877?
CVE-2020-15877 is a vulnerability with a CVSS score of 8.8 (HIGH). An issue was discovered in LibreNMS before 1.65.1. It has insufficient access control for normal users because of "'guard' => 'admin'" instead of "'middleware' => ['can:admin']" in routes/web.php.
How severe is CVE-2020-15877?
CVE-2020-15877 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-15877?
Check the references section above for vendor advisories and patch information. Affected products include: Librenms Librenms.