Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7x92-q8cg-wfh6

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

EPSS

Процентиль: 70%
0.0065
Низкий

Дефекты

CWE-295

Связанные уязвимости

CVSS3: 9.8
nvd
больше 4 лет назад

Incorrect SSL certificate validation in Nagios Fusion 4.1.8 and earlier allows for Escalation of Privileges or Code Execution as root via vectors related to download of an untrusted update package in upgrade_to_latest.sh.

EPSS

Процентиль: 70%
0.0065
Низкий

Дефекты

CWE-295