CVE-2013-2214: Medium severity nagios plugins vulnerability
status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2214?
CVE-2013-2214 has a moderate severity rating due to its potential to disclose sensitive information to authenticated users.
How do I fix CVE-2013-2214?
To fix CVE-2013-2214, upgrade Nagios to version 4.0 beta4 or higher, or to version 3.5.1 or higher.
What is affected by CVE-2013-2214?
CVE-2013-2214 affects Nagios versions 3.0 through 3.5.0 and 4.0 beta1 to 4.0 beta3.
Who is impacted by CVE-2013-2214?
Authenticated users who are listed as contacts for services may be impacted by CVE-2013-2214.
What type of information can be disclosed due to CVE-2013-2214?
CVE-2013-2214 allows unauthorized users to obtain sensitive information about hostnames through service group overviews.