QID 376531

Date Published: 2022-04-27

QID 376531: Nagios XI Docker Wizard Server Side Request Forgery (SSRF) Vulnerability

Nagios Core is a free and open source computer-software application that monitors systems, networks, and infrastructure. This Nagios XI Docker configuration wizard allows two methods for monitoring Docker

Affected versions:
Version prior to 1.1.3

QID Detection Logic:(Authenticated)
QID check for vulnerable versions of Nagios docker wizard from the version file.

Successful exploitation of this vulnerability may allow an authenticated user to server-side request forgery (SSRF) due to improper sanitization in table_population.php.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    The vendor has not released any patch for more information visit here

    CVEs related to QID 376531

    Software Advisories
    Advisory ID Software Component Link
    nagiosxi URL Logo www.nagios.com/products/security/