CVE-2020-13977
Summary
| CVE | CVE-2020-13977 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-06-09 14:15:00 UTC |
| Updated | 2023-11-07 03:17:00 UTC |
| Description | Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: nagios-4.4.6-4.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| [SECURITY] Fedora 33 Update: nagios-4.4.6-3.fc33 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 32 Update: nagios-4.4.6-3.fc32 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Nagios Core 4.x Version History - Nagios |
MISC |
www.nagios.org |
Release Notes, Vendor Advisory |
| [SECURITY] Fedora 33 Update: nagios-4.4.6-3.fc33 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| GitHub - sawolf/nagioscore at url-injection-fix |
MISC |
github.com |
Product, Third Party Advisory |
| Nagios Core 4.4.5 – URL Injection (CVE-2020-13977) |
MISC |
anhtai.me |
Exploit, Third Party Advisory |
| [SECURITY] Fedora 32 Update: nagios-4.4.6-3.fc32 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
Mailing List, Third Party Advisory |
| [SECURITY] Fedora 34 Update: nagios-4.4.6-4.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 281558 Fedora Security Update for nagios (FEDORA-2021-01a2f76cc3)
- 281578 Fedora Security Update for nagios (FEDORA-2021-b5e897a2e5)
- 281579 Fedora Security Update for nagios (FEDORA-2021-5689072a7e)
- 750217 OpenSUSE Security Update for nagios (openSUSE-SU-2021:0715-1)