Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
Advisories

No advisories yet.

Fixes

Solution

Nagios addresses this vulnerability as "Nagios XI would sometimes reveal API keys to users that were not authorized for API access" and "Fixed an issue where an API key was shown to users without API access in Neptune themes."


Workaround

No workaround given by the vendor.

History

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
Title Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-10-30T21:29:37.293Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34283

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2025-10-30T22:15:48.633

Modified: 2025-10-30T22:15:48.633

Link: CVE-2025-34283

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.