Логотип exploitDog
bind:CVE-2025-28059
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-28059

Количество 2

Количество 2

nvd логотип

CVE-2025-28059

10 месяцев назад

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-rw8h-4h76-h2mx

10 месяцев назад

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-28059

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.

CVSS3: 7.5
0%
Низкий
10 месяцев назад
github логотип
GHSA-rw8h-4h76-h2mx

An access control vulnerability in Nagios Network Analyzer 2024R1.0.3 allows deleted users to retain access to system resources due to improper session invalidation and stale token handling. When an administrator deletes a user account, the backend fails to terminate active sessions and revoke associated API tokens, enabling unauthorized access to restricted functions.

CVSS3: 7.5
0%
Низкий
10 месяцев назад

Уязвимостей на страницу