Nagios Log Server
cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*
- < 2024R1.3.1
A code injection vulnerability allowing arbitrary code execution has been identified in Nagios Log Server versions prior to 2024R1.3.1. This vulnerability arises because malformed dashboard ID values are not adequately validated before being sent to an internal API. An attacker who supplies crafted dashboard ID values can manipulate the system to execute their own data, resulting in code execution within the Log Server process.
Exploitation of this vulnerability allows for arbitrary code execution in the context of the Log Server process.
Users are advised to upgrade to Nagios Log Server version 2024R1.3.1 or above.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.