PT-2021-21620 · Nagios Xi · Nagios Xi

Published

2021-08-13

·

Updated

2021-08-23

·

CVE-2021-37352

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Nagios XI versions prior to 5.8.5
Description An open redirect issue exists that could lead to spoofing. To exploit this, an attacker could send a link with a specially crafted URL and convince the user to click the link.
Recommendations For versions prior to 5.8.5, update to version 5.8.5 or later to resolve the issue. As a temporary workaround, consider restricting access to links with specially crafted URLs to minimize the risk of exploitation.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-37352

Affected Products

Nagios Xi