CVE-2021-26024: Medium severity nagios favorites vulnerability
Published Feb 3, 2021
·Updated
The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference: it is possible to create favorites for any other user account.
Affected Software
2 affected components
Nagios Favorites<1.0.2
Nagios Nagios XI=5.8.0
Event History
Feb 3, 2021
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-26024.
2
What is the title of the vulnerability?
The title of the vulnerability is 'The Favorites component before 1.0.2 for Nagios XI 5.8.0 is vulnerable to Insecure Direct Object Reference.'
3
What is the severity of CVE-2021-26024?
The severity of CVE-2021-26024 is medium with a severity value of 5.3.
4
How does the vulnerability impact Nagios XI 5.8.0?
The vulnerability allows an attacker to create favorites for any other user account in Nagios XI 5.8.0.
5
How do I fix the vulnerability?
To fix the vulnerability, update the Favorites component to version 1.0.2 or later.