CVE-2020-35269: CSRF
Published Dec 23, 2020
·Updated
Nagios Core application version 4.2.4 is vulnerable to Site-Wide Cross-Site Request Forgery (CSRF) in many functions, like adding – deleting for hosts or servers.
Affected Software
1 affected component
Nagios Nagios Core=4.2.4
Event History
Dec 23, 2020
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-35269?
CVE-2020-35269 has a medium severity rating due to its potential impact on user session security.
2
How do I fix CVE-2020-35269?
To fix CVE-2020-35269, upgrade Nagios Core to a version newer than 4.2.4 that addresses this CSRF vulnerability.
3
What versions of Nagios Core are affected by CVE-2020-35269?
Nagios Core version 4.2.4 is specifically vulnerable to CVE-2020-35269.
4
What kinds of attacks are possible due to CVE-2020-35269?
CVE-2020-35269 allows attackers to perform unauthorized actions within Nagios Core, such as adding or deleting hosts.
5
Is CVE-2020-35269 a known vulnerability?
Yes, CVE-2020-35269 is a recognized vulnerability that has been cataloged and documented in security databases.