CVE-2018-10553: Path Traversal
Published Apr 30, 2018
·Updated
An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.
Affected Software
1 affected component
Nagios Nagios XI=5.4.13
Event History
Apr 30, 2018
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-10553?
CVE-2018-10553 has a medium severity level due to its potential for unauthorized file access.
2
How do I fix CVE-2018-10553?
To fix CVE-2018-10553, upgrade Nagios XI to the latest version where the vulnerability is patched.
3
Who is affected by CVE-2018-10553?
Anyone using Nagios XI version 5.4.13 is vulnerable to CVE-2018-10553.
4
What type of attack does CVE-2018-10553 allow?
CVE-2018-10553 allows a directory traversal attack, enabling users to read sensitive files on the server.
5
Is there a workaround for CVE-2018-10553?
A temporary workaround for CVE-2018-10553 might include restricting user permissions to limit access to sensitive files.