Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to execute attacker-controlled data, leading to arbitrary code execution in the context of the Log Server process.
The application does not properly validate the dashboard ID parameter values before passing them to the internal API. An attacker can supply deliberately crafted (malformed) dashboard ID values, which are then interpreted and executed by the system. This results in the execution of code controlled by the attacker in the context of the Nagios Log Server process.
An attacker can achieve full control over the Nagios Log Server process by executing arbitrary code (RCE), and due to system-wide attack vectors, potentially threaten the confidentiality, integrity, and availability of both the system itself and related components.
Nagios Log Server must be updated immediately to version 2024R1.3.1 or newer. Detailed patch information is available in the vendor's changelog at https://www.nagios.com/changelog/#log-server-2024R1 and on the vendor's security page https://www.nagios.com/products/security/#log-server
Nagios Log Server in all versions prior to 2024R1.3.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XNagios Log Server
APPNagios2024< 2024
Related vulnerabilities
Nagios Log Server: uruchamianie Logstash z uprawnieniami root (privilege escalation)
Nagios Log Server: ujawnienie kluczy API w postaci jawnej przez authenticated użytkownika
Nagios Log Server versions prior to 2026R1.0.1 are vulnerable to local privilege escalation due to a combinati...
Nagios Log Server versions prior to 2026R1.0.1 contain an authenticated command injection vulnerability in the...
Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked ...