CVE-2026-35588
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix.
वीकनेस
Glances is an open-source system cross-platform monitoring tool. Prior to version 4.5.4, the Cassandra export module (`glances/exports/glances_cassandra/__init__.py`) interpolates `keyspace`, `table`, and `replication_factor` configuration values directly into CQL statements without validation. A user with write access to `glances.conf` can redirect all monitoring data to an attacker-controlled Cassandra keyspace. Version 4.5.4 contains a fix.
प्रभावित प्रोडक्ट
- nicolargo glances
संदर्भ
- https://github.com/nicolargo/glances/commit/d339181f03a14bb15506307e9d58f876e23d8160
- https://github.com/nicolargo/glances/commit/e41b665576f9fd5374e3152078726cc59a01e48c
- https://github.com/nicolargo/glances/security/advisories/GHSA-grp3-h8m8-45p7
- https://github.com/nicolargo/glances/security/advisories/GHSA-grp3-h8m8-45p7
हमलावर से पहले बग आप ढूँढें।
GitHub से साइन इन करें और एक मिनट से भी कम में अपना पहला ऑडिट चलाएँ। फ़्री प्लान के लिए क्रेडिट कार्ड की ज़रूरत नहीं।