CNNVD-202511-1882 Information

CNNVD ID

CNNVD-202511-1882

CVE-2025-34323

  • CNNVD Published: 2025-11-17

Description (Chinese)

Nagios Log Server是美国Nagios公司的一套集中式日志管理、监控和分析软件。 Nagios Log Server 2026R1.0.1之前版本存在安全漏洞,该漏洞源于sudo规则和文件系统权限之间存在不安全交互,可能导致本地权限提升。

Description (English)

Nagios Log Server is a centralized log management, monitoring and analysis software for the United States company Nagios. There was a security gap in the pre-Nagios Log Server 2026R1.0.1 version, which stemmed from the unsafe interaction between the sando rules and the authority of the document system, which could lead to an increase in local authority.

Hazard Level

Medium

Vulnerability Type

其他

Affected Vendor

Nagios

Published

2025-11-17

Last Modified

2026-02-24

References

https://www.nagios.com/products/security/#log-server https://www.nagios.com/changelog/nagios-log-server/nagios-log-server-2026r1-0-1/ https://www.vulncheck.com/advisories/nagios-log-server-local-privilege-escalation-via-writable-scripts-and-sudo-rules https://access.redhat.com/security/cve/cve-2025-34323

Patch

https://www.nagios.com/products/security/#log-server

Share on: