CVE-2022-26308: Improper Access Control in Configuration (Credential store)
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Pandora FMS vulnerability?
The vulnerability ID for this Pandora FMS vulnerability is CVE-2022-26308.
What is the severity of CVE-2022-26308?
The severity of CVE-2022-26308 is medium (5.4).
What is the affected software for CVE-2022-26308?
The affected software for CVE-2022-26308 is Pandora FMS v7.0NG.760 and below.
What is the description of CVE-2022-26308?
CVE-2022-26308 is an improper access control vulnerability in Pandora FMS v7.0NG.760 and below, where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.
How can I fix CVE-2022-26308?
To fix CVE-2022-26308, it is recommended to update Pandora FMS to a version that is not affected by the vulnerability.