CVE-2018-18245: XSS
Published Dec 17, 2018
·Updated
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified checkload plugin to NRPE.
Affected Software
2 affected components
Nagios Nagios Core=4.4.2
Debian Debian Linux=8.0
Event History
Dec 17, 2018
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-18245?
CVE-2018-18245 is classified as a medium severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
2
How do I fix CVE-2018-18245?
You can mitigate CVE-2018-18245 by upgrading Nagios Core to version 4.4.3 or higher which addresses the XSS vulnerability.
3
What versions of Nagios are affected by CVE-2018-18245?
CVE-2018-18245 specifically affects Nagios Core version 4.4.2.
4
Can CVE-2018-18245 be exploited remotely?
Yes, CVE-2018-18245 can be exploited remotely through manipulated plugin results to execute harmful scripts.
5
What types of systems are at risk due to CVE-2018-18245?
Systems running Nagios Core 4.4.2 and certain Debian Linux environments are at risk due to CVE-2018-18245.