Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5w58-vmv5-p957

Опубликовано: 27 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.6

Описание

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

EPSS

Процентиль: 82%
0.01636
Низкий

8.6 High

CVSS3

Дефекты

CWE-491

Связанные уязвимости

CVSS3: 8.6
nvd
3 месяца назад

Nagios Fusion v2024R1.2 and v2024R2 does not invalidate already existing session tokens when the two-factor authentication mechanism is enabled, allowing attackers to perform a session hijacking attack.

EPSS

Процентиль: 82%
0.01636
Низкий

8.6 High

CVSS3

Дефекты

CWE-491