Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
Nagios 4.4.5 allows an attacker, who already has administrative access to
change the "URL for JSON CGIs" configuration setting, to modify the Alert
Histogram and Trends code via crafted versions of the archivejson.cgi,
objectjson.cgi, and statusjson.cgi files (CVE-2020-13977).
- https://bugs.mageia.org/show_bug.cgi?id=28557
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/JUEIABR4Y6L5J5MZDFWU46ZWXMJO64U3/
- https://www.cve.org/CVERecord?id=CVE-2020-13977
- 7/core/nagios-4.4.3-2.1.mga7
Get the latest Linux and open source security news straight to your inbox.