We are getting flagged by our security team for 3 new CVEs added by CISA targeting Nagios xi
https://www.cisa.gov/uscert/ncas/curren ... es-catalog
CVE-2021-25296 Nagios xi OS Command Injection Vulnerability
CVE-2021-25297 Nagios xi OS Command Injection Vulnerability
CVE-2021-25298 Nagios xi OS Command Injection Vulnerability
I know these normally get fixed by the minor version releases, but since there is no set schedule I know of for those releases I wanted to ask a few questions I can take back to my risk management.
1. Is Nagios aware of these CVEs to correct them in the next update?
2. Will that update be out by the February 1st CISA action due date?
xi CVEs
-
- Dreams In Code
- Posts: 7682
- Joined: Wed Feb 11, 2015 12:54 pm
Re: xi CVEs
1. Yes, please see here next to each for the remediation:
https://www.nagios.com/products/security/
What xi version is your system running? You can find it on the bottom left hand side after logging in.
What OS version is the xi server running?
2. They should be fixed if you upgrade to the latest version of xi and upgrade the wizards/components to the latest in Admin > Manage Components and Admin > Manage Wizards. I'll know more based on your responses above.
https://www.nagios.com/products/security/
What xi version is your system running? You can find it on the bottom left hand side after logging in.
What OS version is the xi server running?
Code: Select all
uname -a
cat /etc/*release
-
- Posts: 103
- Joined: Wed Aug 05, 2020 11:39 am
Re: xi CVEs
Nagios 5.8.7 and RHEL 8.4. And that's perfect I had no idea that page or in fact the wizard update are existed. Looking at versions it looks like we're already covered. Thank you!
-
- Dreams In Code
- Posts: 7682
- Joined: Wed Feb 11, 2015 12:54 pm
Re: xi CVEs
You should not be vulnerable based on that.
Let us know when we're okay to close this ticket.
Thank you!
Let us know when we're okay to close this ticket.
Thank you!
-
- Posts: 103
- Joined: Wed Aug 05, 2020 11:39 am
Re: xi CVEs
You're good to lock this thread. Thank you!