Overly permissive cross-domain whitelist in Nagios XI - #VU27087

 

Overly permissive cross-domain whitelist in Nagios XI - #VU27087

Published: April 22, 2020


Vulnerability identifier: #VU27087
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-942
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass security restriction.

The vulnerability exists due to insecure CORS policy that allows a remote attacker to send HTTP requests from arbitrary domain name within the API. A remote non-authenticated attacker can bypass browser security restrictions and send requests to the API endpoints on behalf of the victim.


Affected software

Nagios XI

Remediation

Install updates from vendor's website.

Nagios XI - update to 5.6.14

External References

Related Security Bulletins