Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4f3c-j3m4-8h7h

Опубликовано: 12 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.1
CVSS3: 7.4

Описание

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.

EPSS

Процентиль: 7%
0.00173
Низкий

6.1 Medium

CVSS4

7.4 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.4
ubuntu
27 дней назад

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.

CVSS3: 7.4
nvd
27 дней назад

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cookie. An attacker can supply matching cookie and request parameter values to bypass CSRF protection, enabling unauthenticated attackers to run commands as authorized users via malicious links.

CVSS3: 7.4
debian
27 дней назад

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cros ...

EPSS

Процентиль: 7%
0.00173
Низкий

6.1 Medium

CVSS4

7.4 High

CVSS3

Дефекты

CWE-352