Unrated severityOSV Advisory· Published Dec 17, 2018· Updated Aug 5, 2024
CVE-2018-18245
CVE-2018-18245
Description
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
Affected products
5- Range: =4.4.2
- osv-coords3 versionspkg:rpm/opensuse/nagios&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/nagios&distro=openSUSE%20Tumbleweedpkg:rpm/suse/nagios&distro=SUSE%20Package%20Hub%2015%20SP1
< 4.4.5-lp151.5.4.1+ 2 more
- (no CPE)range: < 4.4.5-lp151.5.4.1
- (no CPE)range: < 4.4.6-2.5
- (no CPE)range: < 4.4.5-bp151.4.3.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.opensuse.org/opensuse-security-announce/2020-04/msg00014.htmlmitrevendor-advisoryx_refsource_SUSE
- lists.opensuse.org/opensuse-security-announce/2020-04/msg00022.htmlmitrevendor-advisoryx_refsource_SUSE
- herolab.usd.de/wp-content/uploads/sites/4/2018/12/usd20180026.txtmitrex_refsource_MISC
- lists.debian.org/debian-lts-announce/2018/12/msg00014.htmlmitremailing-listx_refsource_MLIST
News mentions
0No linked articles in our index yet.