Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gpq7-64xq-65r5

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.7
CVSS3: 8.1

Описание

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could allow authenticated but non-privileged users to read or modify resources beyond their intended rights.

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could allow authenticated but non-privileged users to read or modify resources beyond their intended rights.

EPSS

Процентиль: 52%
0.00293
Низкий

8.7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-863

Связанные уязвимости

CVSS3: 8.1
nvd
3 месяца назад

Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could allow authenticated but non-privileged users to read or modify resources beyond their intended rights.

CVSS3: 8.8
fstec
около 2 лет назад

Уязвимость интерфейса программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю получить доступ на чтение и изменение данных

EPSS

Процентиль: 52%
0.00293
Низкий

8.7 High

CVSS4

8.1 High

CVSS3

Дефекты

CWE-863