Логотип exploitDog
bind:CVE-2025-34322
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-34322

Количество 3

Количество 3

nvd логотип

CVE-2025-34322

3 месяца назад

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selection and connection parameters—are read from the global configuration and concatenated into a shell command that is executed via shell_exec() without proper input handling or command-line argument sanitation. An authenticated user with access to the 'Global Settings' page can supply crafted values in these fields to inject additional shell commands, resulting in arbitrary command execution as the 'www-data' user and compromise of the Log Server host.

CVSS3: 7.2
EPSS: Низкий
github логотип

GHSA-qrg4-jqvv-5724

3 месяца назад

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability via the experimental 'Natural Language Queries' feature. Configuration values for this feature are read from the application settings and incorporated into a system command without adequate validation or restriction of special characters. An authenticated user with access to global configuration can abuse these settings to execute arbitrary operating system commands with the privileges of the web server account, leading to compromise of the Log Server host.

CVSS3: 7.2
EPSS: Низкий
fstec логотип

BDU:2025-14541

3 месяца назад

Уязвимость функции Natural Language Queries программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-34322

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selection and connection parameters—are read from the global configuration and concatenated into a shell command that is executed via shell_exec() without proper input handling or command-line argument sanitation. An authenticated user with access to the 'Global Settings' page can supply crafted values in these fields to inject additional shell commands, resulting in arbitrary command execution as the 'www-data' user and compromise of the Log Server host.

CVSS3: 7.2
0%
Низкий
3 месяца назад
github логотип
GHSA-qrg4-jqvv-5724

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability via the experimental 'Natural Language Queries' feature. Configuration values for this feature are read from the application settings and incorporated into a system command without adequate validation or restriction of special characters. An authenticated user with access to global configuration can abuse these settings to execute arbitrary operating system commands with the privileges of the web server account, leading to compromise of the Log Server host.

CVSS3: 7.2
0%
Низкий
3 месяца назад
fstec логотип
BDU:2025-14541

Уязвимость функции Natural Language Queries программного средства мониторинга и анализа логов Nagios Log Server, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.2
0%
Низкий
3 месяца назад

Уязвимостей на страницу