Логотип exploitDog
bind:CVE-2025-34270
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-34270

Количество 3

Количество 3

nvd логотип

CVE-2025-34270

3 месяца назад

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

CVSS3: 4.9
EPSS: Низкий
github логотип

GHSA-6577-56w8-v2rg

3 месяца назад

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

CVSS3: 4.9
EPSS: Низкий
fstec логотип

BDU:2025-15423

7 месяцев назад

Уязвимость функции импорта пользователей из AD/LDAP программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-34270

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

CVSS3: 4.9
0%
Низкий
3 месяца назад
github логотип
GHSA-6577-56w8-v2rg

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

CVSS3: 4.9
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-15423

Уязвимость функции импорта пользователей из AD/LDAP программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 4.9
0%
Низкий
7 месяцев назад

Уязвимостей на страницу