status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2013-2168 status.cgi in Nagios 4.0 before 4.0 beta4 and 3.x before 3.5.1 does not properly restrict access to certain users that are a contact for a service, which allows remote authenticated users to obtain sensitive information about hostnames via the servicegroup (1) overview, (2) summary, or (3) grid style in status.cgi. NOTE: this behavior is by design in most 3.x versions, but the upstream vendor "decided to change it for Nagios 4" and 3.5.1.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-06T15:27:41.093Z

Reserved: 2013-02-19T00:00:00

Link: CVE-2013-2214

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2014-02-10T23:55:04.963

Modified: 2025-04-11T00:51:21.963

Link: CVE-2013-2214

cve-icon Redhat

Severity : Moderate

Publid Date: 2013-05-06T00:00:00Z

Links: CVE-2013-2214 - Bugzilla

cve-icon OpenCVE Enrichment

No data.