Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-2214

Опубликовано: 10 фев. 2014
Источник: nvd
CVSS2: 4
EPSS Низкий

Описание

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:nagios:nagios:3.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta4:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta5:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta6:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:beta7:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:rc1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:rc2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0:rc3:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0.2:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0.3:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0.4:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0.5:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.0.6:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.1.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.1.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.1.2:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.2.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.2.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.2.2:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.2.3:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.3.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.4.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.4.1:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.4.3:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.4.4:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:3.5.0:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios:4.0.0:beta3:*:*:*:*:*:*

EPSS

Процентиль: 86%
0.02677
Низкий

4 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

ubuntu
почти 12 лет назад

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.

redhat
почти 13 лет назад

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.

debian
почти 12 лет назад

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does no ...

github
больше 3 лет назад

status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.

EPSS

Процентиль: 86%
0.02677
Низкий

4 Medium

CVSS2

Дефекты

CWE-264