在 Nagios Core 4.5.12 之前的版本中, 存在跨站请求伪造(CSRF)漏洞。该漏洞的成因是:当 Cookie 缺失时,CSRF 防护机制未能有效拦截,导致验证通过。攻击者可构造恶意的跨站 POST 请求,利用当前已认证用户的身份,在用户不知晓或未经其同意的情况下,执行任意的 Nagios 命令。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Nagios Enterprises, LLC. | Nagios Core | < 4.5.12 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Nagios Enterprises, LLC. | Nagios Core | 0 ~ 4.5.12 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet