CVE-2023-37154: Command Injection
checkbyssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-37154?
CVE-2023-37154 has been categorized as a medium to high severity vulnerability due to the potential for arbitrary command execution.
How do I fix CVE-2023-37154?
To mitigate CVE-2023-37154, upgrade Nagios nagios-plugins to the latest version where the vulnerability has been addressed.
What systems are affected by CVE-2023-37154?
CVE-2023-37154 affects Nagios nagios-plugins version 2.4.5 and potentially earlier releases.
What kind of attack does CVE-2023-37154 allow?
CVE-2023-37154 allows an attacker to execute arbitrary commands using certain command execution options in Nagios.
Is CVE-2023-37154 an intended behavior in Nagios?
CVE-2023-37154 has been characterized as both fixed and as intended behavior based on its implementation with ProxyCommand and LocalCommand.