Nagios Log Server versions prior to 2024R2.0.3 contain an execution with unnecessary privileges vulnerability as it runs its embedded Logstash process as the root user. If an attacker is able to compromise the Logstash process - for example by exploiting an insecure plugin, pipeline configuration injection, or a vulnerability in input parsing - the attacker could execute code with root privileges, resulting in full system compromise. The Logstash service has been altered to run as the lower-privileged 'nagios' user to reduce this risk associated with a network-facing service that can accept untrusted input or load third-party components.
The built-in Logstash process, which is a network service accepting potentially untrusted input, runs with the highest system privileges (root). An attacker can compromise it through various methods: by exploiting vulnerabilities in unsafe plugins, injecting pipeline configuration, or exploiting vulnerabilities in input data parsing mechanisms. Since Logstash accepts data from the network and can load external vendor components, the attack surface is extensive. After successful compromise of the Logstash process, any executed code automatically runs with root privileges.
An attacker who gains control over the Logstash process can execute arbitrary code with root privileges, leading to complete compromise of the operating system — including reading and modifying all data, installing backdoors, and lateral movement within the network.
Update Nagios Log Server to version 2024R2.0.3 or later. In this version, the Logstash service has been changed to run under the unprivileged 'nagios' user account instead of root. Details of the fix are available in the vendor's official changelog and on the Nagios security page.
Nagios Log Server in versions earlier than 2024R2.0.3
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNagios Log Server
APPNagios2024< 2024
Related vulnerabilities
RCE w Nagios Log Server — code injection przez malformed dashboard ID
Nagios Log Server: ujawnienie kluczy API w postaci jawnej przez authenticated użytkownika
Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combinati...
Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the...
Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked ...