Nagios Log Server
cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*
- < 2024R1
A vulnerability exists in Nagios Log Server versions prior to 2024R1, where incorrect authorization allows users without the necessary API permissions to access API endpoints. This flaw enables authenticated but non-privileged users to read or modify resources beyond their authorized rights, leading to unintended access to data and actions available through the API.
Exploitation of this vulnerability could result in unauthorized access to data and actions via the API, allowing users to read or modify resources beyond their intended rights.
Users can upgrade to Nagios Log Server version 2024R1 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.