Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7429-79p7-vgcx

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 9.2
CVSS3: 9.8

Описание

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.

EPSS

Процентиль: 45%
0.00226
Низкий

9.2 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-613

Связанные уязвимости

CVSS3: 9.8
nvd
3 месяца назад

Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.

CVSS3: 9.4
fstec
3 месяца назад

Уязвимость инструмента для мониторинга ИТ-инфраструктуры Nagios XI, связанная с неверным сроком действия сеанса, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 45%
0.00226
Низкий

9.2 Critical

CVSS4

9.8 Critical

CVSS3

Дефекты

CWE-613