Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cxmv-3hc7-9rh3

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.8

Описание

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.

EPSS

Процентиль: 23%
0.00076
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-281

Связанные уязвимости

CVSS3: 8.8
nvd
3 месяца назад

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied to email identity state, trigger inconsistent account state that granted elevated privileges or bypassed intended access controls.

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость программного средства для мониторинга и анализа журналов в ИТ-инфраструктуре Nagios Log Server, связанная с неправильным сохранением разрешений, позволяющая нарушителю обойти существующие ограничения безопасности и повысить свои привилегии

EPSS

Процентиль: 23%
0.00076
Низкий

8.7 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-281