CVE-2023-38349: CSRF
Published Jul 15, 2023
·Updated
PNP4Nagios through 81ebfc5 lacks CSRF protection in the AJAX controller. This affects 0.6.26.
Affected Software
1 affected component
PNP4Nagios PNP4Nagios=0.6.26
Event History
Jul 15, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
02:15 AM
Description
Data Sourced
via NVD·02:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-38349?
CVE-2023-38349 is considered a moderate severity vulnerability due to the lack of CSRF protection in the AJAX controller.
2
How do I fix CVE-2023-38349?
To fix CVE-2023-38349, update PNP4Nagios to version 0.6.27 or later where the CSRF protection issue is addressed.
3
What software versions are affected by CVE-2023-38349?
CVE-2023-38349 affects PNP4Nagios version 0.6.26.
4
What type of vulnerability is CVE-2023-38349?
CVE-2023-38349 is a Cross-Site Request Forgery (CSRF) vulnerability.
5
Who is impacted by CVE-2023-38349?
Users of PNP4Nagios version 0.6.26 are impacted by CVE-2023-38349 due to insufficient CSRF protection.