CVE-2021-35479
Summary
| CVE | CVE-2021-35479 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-30 14:15:00 UTC |
| Updated | 2022-02-10 17:06:00 UTC |
| Description | Nagios Log Server before 2.1.9 contains Stored XSS in the custom column view for the alert history and audit log function through the affected pp parameter. This affects users who open a crafted link or third-party web page. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Nagios | Log Server | All | All | All | All |
| Application | Naigos | Nagios Log Server | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Technical Advisory: Stored and Reflected XSS Vulnerability in Nagios Log Server (CVE-2021-35478,CVE-2021-35479) – NCC Group Research | MISC | research.nccgroup.com | |
| NCC Group Research Blog | Making the world safer and more secure | MISC | research.nccgroup.com | |
| Nagios Log Server Change Log - Nagios | MISC | www.nagios.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.