Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade nagios4 | Feb 20, 2019 | Dec 17, 2018 |
| Suse | — | Upgrade nagios-theme-exfoliationUpgrade nagios-www-dchUpgrade nagios-wwwUpgrade nagiosUpgrade nagios-contribUpgrade nagios-devel | Apr 12, 2020 | Dec 17, 2018 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Dec 17, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub