PT-2023-3899 · Unknown · Pnp4Nagios
Schnudd31Do3
·
Published
2023-07-09
·
Updated
2023-07-26
·
CVE-2023-38349
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
PNP4Nagios versions 0.6.26 and prior to version 81ebfc5
Description
The issue is related to a lack of CSRF protection in the AJAX controller of the PNP4Nagios performance analyzer, which is part of the Nagios network monitoring system. This allows a remote attacker to perform a CSRF attack.
Recommendations
For PNP4Nagios version 0.6.26, consider disabling the AJAX controller until a patch is available.
For versions prior to 81ebfc5, restrict access to the AJAX controller to minimize the risk of exploitation.
As a temporary workaround, avoid using the vulnerable AJAX controller functionality until the issue is resolved.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pnp4Nagios