CVE-2021-37347: Path Traversal
Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XIto a version that resolves this vulnerability.Fixed in 5.8.5
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2021-37347.
What is the title of this vulnerability?
The title of this vulnerability is 'Nagios XI before version 5.8.5 is vulnerable to local privilege escalation because getprofile.sh does not validate the directory name it receives as an argument.'
What is the severity of CVE-2021-37347?
The severity of CVE-2021-37347 is high with a severity value of 7.8.
What software is affected by this vulnerability?
The software affected by this vulnerability is Nagios XI before version 5.8.5.
How can I fix CVE-2021-37347?
To fix CVE-2021-37347, you should upgrade Nagios XI to version 5.8.5 or later.