Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5v2w-q8v2-gpf9

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 5.3
CVSS3: 6.5

Описание

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's dashboard sharing and access policies, this behavior may cause information exposure or unexpected privilege exposure.

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's dashboard sharing and access policies, this behavior may cause information exposure or unexpected privilege exposure.

EPSS

Процентиль: 78%
0.01097
Низкий

5.3 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 6.5
nvd
3 месяца назад

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's dashboard sharing and access policies, this behavior may cause information exposure or unexpected privilege exposure.

CVSS3: 6.5
fstec
6 месяцев назад

Уязвимость панели мониторинга программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю раскрыть защищаемую информацию

EPSS

Процентиль: 78%
0.01097
Низкий

5.3 Medium

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-200