Nagios

Log Server

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.01%
  • Veröffentlicht 17.11.2025 17:48:28
  • Zuletzt bearbeitet 26.11.2025 15:15:52

Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combination of sudo misconfiguration and group-writable application directories. The 'www-data' user is a member of the 'nagios' group, which has wri...

  • EPSS 0.44%
  • Veröffentlicht 17.11.2025 17:48:04
  • Zuletzt bearbeitet 26.11.2025 15:15:51

Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. When this feature is configured, certain user-controlled settings—including model selectio...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:27:23
  • Zuletzt bearbeitet 05.11.2025 18:21:01

Nagios Log Server versions prior to 2.1.14 are vulnerable to cross-site scripting (XSS) via the Snapshots Page. Untrusted log content was not safely encoded for the output context, allowing attacker-controlled data present in logs to execute script i...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:27:03
  • Zuletzt bearbeitet 06.11.2025 16:20:27

Nagios Log Server versions prior to 2024R1 are vulnerable to cross-site scripting (XSS) via the Create User function. Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the conte...

  • EPSS 0.43%
  • Veröffentlicht 30.10.2025 21:26:38
  • Zuletzt bearbeitet 05.11.2025 18:25:04

Nagios Log Server versions prior to 2.1.6 contain cross-site scripting (XSS) vulnerabilities via the web interface on the Create User, Edit User, and Manage Host Lists pages. Insufficient validation or escaping of user-supplied input may allow an att...

  • EPSS 0.13%
  • Veröffentlicht 30.10.2025 21:26:13
  • Zuletzt bearbeitet 10.11.2025 19:15:45

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it is a duplicate of CVE-2023-7323.

  • EPSS 0.07%
  • Veröffentlicht 30.10.2025 21:25:52
  • Zuletzt bearbeitet 06.11.2025 16:27:12

Nagios Log Server versions prior to 2024R1.3.2 contain a privilege escalation vulnerability in the account email-change workflow. A user could set their own email to an invalid value and, due to insufficient validation and authorization checks tied t...

  • EPSS 0.21%
  • Veröffentlicht 30.10.2025 21:25:32
  • Zuletzt bearbeitet 06.11.2025 16:27:31

Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can...

  • EPSS 0.95%
  • Veröffentlicht 30.10.2025 21:25:10
  • Zuletzt bearbeitet 06.11.2025 16:29:24

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard b...

  • EPSS 0.19%
  • Veröffentlicht 30.10.2025 21:24:43
  • Zuletzt bearbeitet 06.11.2025 16:28:38

Nagios Log Server versions prior to 2024R2.0.3 contain an incorrect authorization vulnerability that allows non-administrator users to delete global dashboards. The application did not correctly enforce authorization checks for the global dashboard d...