{"api_version":"1","generated_at":"2026-07-23T12:56:32+00:00","cve":"CVE-2020-13977","urls":{"html":"https://cve.report/CVE-2020-13977","api":"https://cve.report/api/cve/CVE-2020-13977.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-13977","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-13977"},"summary":{"title":"CVE-2020-13977","description":"Nagios 4.4.5 allows an attacker, who already has administrative access to change the \"URL for JSON CGIs\" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2020-06-09 14:15:00","updated_at":"2023-11-07 03:17:00"},"problem_types":["CWE-829"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/5P6NHNG2SJAM6DXVTXQH3AOJ4WQVKJUE/","name":"FEDORA-2021-01a2f76cc3","refsource":"","tags":[],"title":"[SECURITY] Fedora 34 Update: nagios-4.4.6-4.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JUEIABR4Y6L5J5MZDFWU46ZWXMJO64U3/","name":"FEDORA-2021-5689072a7e","refsource":"FEDORA","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 33 Update: nagios-4.4.6-3.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H7T6MSDWMBJEVVFSOK7DOYJJWDAFQCEQ/","name":"FEDORA-2021-b5e897a2e5","refsource":"","tags":[],"title":"[SECURITY] Fedora 32 Update: nagios-4.4.6-3.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.nagios.org/projects/nagios-core/history/4x/","name":"https://www.nagios.org/projects/nagios-core/history/4x/","refsource":"MISC","tags":["Release Notes","Vendor Advisory"],"title":"Nagios Core 4.x Version History - Nagios","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JUEIABR4Y6L5J5MZDFWU46ZWXMJO64U3/","name":"FEDORA-2021-5689072a7e","refsource":"","tags":[],"title":"[SECURITY] Fedora 33 Update: nagios-4.4.6-3.fc33 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/sawolf/nagioscore/tree/url-injection-fix","name":"https://github.com/sawolf/nagioscore/tree/url-injection-fix","refsource":"MISC","tags":["Product","Third Party Advisory"],"title":"GitHub - sawolf/nagioscore at url-injection-fix","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://anhtai.me/nagios-core-4-4-5-url-injection/","name":"https://anhtai.me/nagios-core-4-4-5-url-injection/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Nagios Core 4.4.5 – URL Injection (CVE-2020-13977)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H7T6MSDWMBJEVVFSOK7DOYJJWDAFQCEQ/","name":"FEDORA-2021-b5e897a2e5","refsource":"FEDORA","tags":["Mailing List","Third Party Advisory"],"title":"[SECURITY] Fedora 32 Update: nagios-4.4.6-3.fc32 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5P6NHNG2SJAM6DXVTXQH3AOJ4WQVKJUE/","name":"FEDORA-2021-01a2f76cc3","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 34 Update: nagios-4.4.6-4.fc34 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-13977","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-13977","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"13977","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"32","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13977","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"33","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13977","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"fedoraproject","cpe5":"fedora","cpe6":"34","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13977","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"nagios","cpe6":"4.4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2020","cve_id":"13977","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"nagios","cpe5":"nagios","cpe6":"4.4.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-13977","qid":"281558","title":"Fedora Security Update for nagios (FEDORA-2021-01a2f76cc3)"},{"cve":"CVE-2020-13977","qid":"281578","title":"Fedora Security Update for nagios (FEDORA-2021-b5e897a2e5)"},{"cve":"CVE-2020-13977","qid":"281579","title":"Fedora Security Update for nagios (FEDORA-2021-5689072a7e)"},{"cve":"CVE-2020-13977","qid":"750217","title":"OpenSUSE Security Update for nagios (openSUSE-SU-2021:0715-1)"}]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2020-13977","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Nagios 4.4.5 allows an attacker, who already has administrative access to change the \"URL for JSON CGIs\" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://anhtai.me/nagios-core-4-4-5-url-injection/","refsource":"MISC","name":"https://anhtai.me/nagios-core-4-4-5-url-injection/"},{"url":"https://www.nagios.org/projects/nagios-core/history/4x/","refsource":"MISC","name":"https://www.nagios.org/projects/nagios-core/history/4x/"},{"url":"https://github.com/sawolf/nagioscore/tree/url-injection-fix","refsource":"MISC","name":"https://github.com/sawolf/nagioscore/tree/url-injection-fix"},{"refsource":"FEDORA","name":"FEDORA-2021-b5e897a2e5","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H7T6MSDWMBJEVVFSOK7DOYJJWDAFQCEQ/"},{"refsource":"FEDORA","name":"FEDORA-2021-5689072a7e","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/JUEIABR4Y6L5J5MZDFWU46ZWXMJO64U3/"},{"refsource":"FEDORA","name":"FEDORA-2021-01a2f76cc3","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5P6NHNG2SJAM6DXVTXQH3AOJ4WQVKJUE/"}]}},"nvd":{"publishedDate":"2020-06-09 14:15:00","lastModifiedDate":"2023-11-07 03:17:00","problem_types":["CWE-829"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"HIGH","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseScore":4.9,"baseSeverity":"MEDIUM"},"exploitabilityScore":1.2,"impactScore":3.6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:nagios:nagios:4.4.5:*:*:*:*:*:*:*","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"13977","Ordinal":"175203","Title":"CVE-2020-13977","CVE":"CVE-2020-13977","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"13977","Ordinal":"1","NoteData":"Nagios 4.4.5 allows an attacker, who already has administrative access to change the \"URL for JSON CGIs\" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"13977","Ordinal":"2","NoteData":"2020-06-09","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"13977","Ordinal":"3","NoteData":"2021-03-19","Type":"Other","Title":"Modified"}]}}}