First published: Mon May 24 2021(Updated: )
Incorrect Access Control in Nagios Fusion 4.1.8 and earlier allows low-privileged authenticated users to extract passwords used to manage fused servers via the test_server command in ajaxhelper.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Nagios Fusion | <=4.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28911 is a vulnerability in Nagios Fusion 4.1.8 and earlier that allows low-privileged authenticated users to extract passwords used to manage fused servers.
The severity of CVE-2020-28911 is medium with a CVSS score of 6.5.
Low-privileged authenticated users can exploit CVE-2020-28911 by using the test_server command in ajaxhelper.php to extract passwords used to manage fused servers.
The affected software for CVE-2020-28911 is Nagios Fusion 4.1.8 and earlier.
Yes, it is recommended to update to a version of Nagios Fusion that is newer than 4.1.8 to fix CVE-2020-28911.