In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's dashboard sharing and access policies, this behavior may cause information exposure or unexpected privilege exposure.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Oct 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nagios
Nagios log Server |
|
| Vendors & Products |
Nagios
Nagios log Server |
Thu, 30 Oct 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Nagios Log Server versions prior to 2024R2.0.3, when a user's configured default dashboard is deleted, the application does not reliably fall back to an empty, default dashboard. In some implementations this can result in an unexpected dashboard being presented as the user's default view. Depending on the product's dashboard sharing and access policies, this behavior may cause information exposure or unexpected privilege exposure. | |
| Title | Nagios Log Server < 2024R2.0.3 Non-Empty Default Dashboard Fallback | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2025-10-30T21:25:10.601Z
Updated: 2025-10-31T17:25:33.564Z
Reserved: 2025-04-15T19:15:22.580Z
Link: CVE-2025-34272
Updated: 2025-10-31T17:25:27.087Z
Status : Received
Published: 2025-10-30T22:15:47.810
Modified: 2025-10-30T22:15:47.810
Link: CVE-2025-34272
No data.