Alerts This Week
Warning Icon 1 1,234
Alerts This Week
Warning Icon 1 1,234

Debian LTS: DLA-4149-1 critical: nagvis path traversal & RCE

debian lts
Calendar Grey May 1, 2025
Dist Debian Esm H88
The latest Nagvis patch for Debian LTS resolves serious vulnerabilities, encompassing remote command execution and cross-site scripting (XSS) concerns.
Multiple vulnerabilities were discovered in nagvis, a visualization addon for Nagios or Icinga

Summary

CVE-2021-33178

Due to an authenticated path traversal vulnerability, a malicious actor
has the ability to arbitrarily delete files on the local system.

CVE-2022-3979

Due to a type juggling vulnerability, a remote attacker could
successfully guess an authentication cookie.

CVE-2022-46945

An attacker can read arbitrary files.

CVE-2023-46287

A XSS vulnerability exists in a function.

CVE-2024-13722 / CVE-2024-47093

Multiple XSS vulnerabilities exist.

CVE-2024-13723 / CVE-2024-47093

Multiple RCE vulnerabilities exist. An authenticated attacker with
administrative level privileges is able to upload a malicious PHP file
and modify specific settings to execute the contents of the file as
PHP.

For Debian 11 bullseye, these problems have been fixed in version
1:1.9.25-2+deb11u1.

We recommend that you upgrade your nagvis packages.

For the detailed security status of nagvis please refer to
its security tracker page at:

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: nagvis
Version: 1:1.9.25-2+deb11u1
CVE ID: CVE-2021-33178 CVE-2022-3979 CVE-2022-46945 CVE-2023-46287

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here