Cross-Site Request Forgery Vulnerability in Nagios Core Application
CVE-2020-35269

8.8HIGH

Key Information:

Vendor

Nagios

Vendor
CVE Published:
23 December 2020

What is CVE-2020-35269?

The Nagios Core application version 4.2.4 has a vulnerability that allows malicious actors to exploit Site-Wide Cross-Site Request Forgery (CSRF). This vulnerability affects multiple functions within the application, enabling attackers to perform unauthorized actions such as adding or deleting hosts or servers without proper verification. The flaw emphasizes the importance of implementing secure request validation mechanisms to prevent exploitation.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.