Vulnerability Name: | CVE-2020-13977 (CCN-183368) | ||||||||||||||||||||||||||||||||
Assigned: | 2020-06-03 | ||||||||||||||||||||||||||||||||
Published: | 2020-06-03 | ||||||||||||||||||||||||||||||||
Updated: | 2021-07-21 | ||||||||||||||||||||||||||||||||
Summary: | Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. Note: this vulnerability has been mistakenly associated with CVE-2020-1408. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N) 4.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:U/RL:U/RC:R)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-74 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-13977 Source: CCN Type: Aishee Blog, June 3, 2020 Nagios Core 4.4.5 URL Injection (CVE-2020-13977) Source: MISC Type: Exploit, Third Party Advisory https://anhtai.me/nagios-core-4-4-5-url-injection/ Source: XF Type: UNKNOWN nagios-cve202013977-sec-bypass(183368) Source: MISC Type: Product, Third Party Advisory https://github.com/sawolf/nagioscore/tree/url-injection-fix Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-01a2f76cc3 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-b5e897a2e5 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-5689072a7e Source: CCN Type: Nagios Web site Nagios - The Industry Standard In IT Infrastructure Monitoring Source: MISC Type: Release Notes, Vendor Advisory https://www.nagios.org/projects/nagios-core/history/4x/ | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |