CVE-2013-2214
Publication date 10 February 2014
Last updated 4 August 2025
Ubuntu priority
status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.
Status
Package | Ubuntu Release | Status |
---|---|---|
icinga | ||
nagios3 | ||
Notes
seth-arnold
Icinga asserts not-affected despite reports to the contrary
mdeslaur
this CVE has been rejected: http://www.openwall.com/lists/oss-security/2013/08/02/3
Patch details
Package | Patch details |
---|---|
nagios3 |