CNNVD-202510-4091 Information
CNNVD ID
CNNVD-202510-4091
Related CVE
- CNNVD Published: 2025-10-30
Description (Chinese)
Nagios Log Server是美国Nagios公司的一套集中式日志管理、监控和分析软件。 Nagios Log Server 2024R2.0.2之前版本存在安全漏洞,该漏洞源于AD或LDAP用户导入功能未能混淆密码字段,可能导致明文密码泄露。
Description (English)
Nagios Log Server is a centralized log management, monitoring and analysis software for the United States company Nagios. There was a security loophole in the pre-Nagios Log Server 2024R2.0.2 version, which stemmed from the failure of AD or LDAP user import functions to confuse password fields, which could lead to the disclosure of an explicit password.
Hazard Level
High
Vulnerability Type
其他
Affected Vendor
Nagios
Published
2025-10-30
Last Modified
2026-02-24
References
https://support.nagios.com/kb/article/authenticating-and-importing-users-with-ad-and-ldap-995.html https://www.nagios.com/changelog/#log-server https://www.nagios.com/products/security/#log-server-2024R2 https://www.vulncheck.com/advisories/nagios-log-server-ad-ldap-import-password-not-obfuscated
Patch
https://www.nagios.com/products/security/#log-server-2024R2
Share on: