Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-gvrp-ffhh-698m

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.4
CVSS3: 7.8

Описание

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.

EPSS

Процентиль: 1%
0.00012
Низкий

8.4 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
nvd
3 месяца назад

Nagios XI versions prior to 2024R2 contain an improperly owned script, process_perfdata.pl, which is executed periodically as the nagios user but owned by www-data. Because the file was writable by www-data, an attacker with web server privileges could modify its contents, leading to arbitrary code execution as the nagios user when the script is next run. This improper ownership and permission configuration enables local privilege escalation.

CVSS3: 7.3
fstec
3 месяца назад

Уязвимость сценария process_perfdata.pl инструмента для мониторинга ИТ-инфраструктуры Nagios XI, позволяющая нарушителю повысить свои привилегии и выполнить произвольный код

EPSS

Процентиль: 1%
0.00012
Низкий

8.4 High

CVSS4

7.8 High

CVSS3

Дефекты

CWE-732