The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
References
Link | Resource |
---|---|
https://www.nagios.com/products/security/ | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Information
Published : 2021-02-03 14:15
Updated : 2021-02-05 11:33
NVD link : CVE-2021-26024
Mitre link : CVE-2021-26024
JSON object : View
CWE
Products Affected
nagios
- favorites
- nagios_xi