Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-rmp9-wcq5-wff8

Опубликовано: 31 окт. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 7.3
CVSS3: 7

Описание

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.

EPSS

Процентиль: 3%
0.00016
Низкий

7.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-367

Связанные уязвимости

CVSS3: 7
nvd
3 месяца назад

Nagios XI versions prior to 2011R1.9 contain privilege escalation vulnerabilities in the scripts that install or update system crontab entries. Due to time-of-check/time-of-use race conditions and missing synchronization or final-path validation, a local low-privileged user could manipulate filesystem state during crontab installation to influence the files or commands executed with elevated privileges, resulting in execution with higher privileges.

EPSS

Процентиль: 3%
0.00016
Низкий

7.3 High

CVSS4

7 High

CVSS3

Дефекты

CWE-367