Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c962-q9ch-7qhw

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files.

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files.

EPSS

Процентиль: 83%
0.01872
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 4.9
ubuntu
больше 5 лет назад

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.

CVSS3: 4.9
nvd
больше 5 лет назад

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.

CVSS3: 4.9
debian
больше 5 лет назад

Nagios 4.4.5 allows an attacker, who already has administrative access ...

suse-cvrf
больше 4 лет назад

Security update for nagios

EPSS

Процентиль: 83%
0.01872
Низкий

Дефекты

CWE-74