4
CVSSv2

CVE-2020-13977

Published: 09/06/2020 Updated: 07/11/2023
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N

Vulnerability Summary

Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nagios nagios 4.4.5

fedoraproject fedora 32

fedoraproject fedora 33

fedoraproject fedora 34

Vendor Advisories

Debian Bug report logs - #962826 nagios4: CVE-2020-13977 Package: src:nagios4; Maintainer for src:nagios4 is Russell Stuart <russell-debian@stuartidau>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 Jun 2020 19:09:01 UTC Severity: important Tags: security, upstream Found in version nagios4/4 ...