Описание
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| nagios4 | unfixed | package |
Примечания
https://gist.github.com/MoSalah20/d1d40b43eafba0bd22ee4cddecad3cbc
https://github.com/NagiosEnterprises/nagioscore/issues/809
Negligible security impact, only affects inherently insecure setups
EPSS
Связанные уязвимости
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
There is a Cross Site Request Forgery (CSRF) vulnerability in Nagios Core 4.2.4.
EPSS