CVE-2021-37353: SSRF
Published Aug 13, 2021
·Updated
Nagios XI Docker Wizard before version 1.1.3 is vulnerable to SSRF due to improper sanitation in tablepopulation.php.
Affected Software
1 affected component
Nagios Nagios XI Docker Wizard<1.1.3
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Nagios XI Docker Wizardto a version that resolves this vulnerability.Fixed in 1.1.3
Event History
Aug 13, 2021
CVE Published
via MITRE·11:29 AM
Data Sourced
via MITRE·11:29 AM
Description
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for Nagios XI Docker Wizard?
The vulnerability ID for Nagios XI Docker Wizard is CVE-2021-37353.
2
What is the severity level of CVE-2021-37353?
The severity level of CVE-2021-37353 is critical with a CVSS score of 9.8.
3
What is affected by CVE-2021-37353?
Nagios XI Docker Wizard versions up to 1.1.3 are affected by CVE-2021-37353.
4
How does CVE-2021-37353 exploit the vulnerability?
CVE-2021-37353 exploits a Server-Side Request Forgery (SSRF) vulnerability due to improper sanitation in table_population.php.
5
Is there a fix available for CVE-2021-37353?
Yes, updating Nagios XI Docker Wizard to version 1.1.3 or later will fix the vulnerability.