← Back

CVE-2025-34272

nvd nist
Published: Oct 30, 2025Modified: Jun 17, 2026

JSON object

Loading...
5.3
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: disclosure@vulncheck.com (Secondary)

Description

In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's dashboard sharing and access policies, this behavior may cause information exposure or unexpected privilege exposure.

Affected (15)

Products: Nagios: Log Server
1 product
Log Server
Configuration A
15 vulnerable
Vulnerable SoftwareAffected Versions
Nagios
Before 2024
Version 2024 r1.0.1
Version 2024 r1.0.2
Version 2024 r1.1
Version 2024 r1.2
Version 2024 r1.3.1
Version 2024 r1.3.2
Version 2024 r1.3.3
Version 2024 r1.3.4
Version 2024 r1.3.5
Version 2024 r1.3
Version 2024 r1
Version 2024 r2.0.1
Version 2024 r2.0.2
Version 2024 r2

References (3)

Source: disclosure@vulncheck.com
Release Notes
Source: disclosure@vulncheck.com
Vendor Advisory

Timeline

No history available yet.