Nagios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could allow authenticated but non-privileged users to read or modify resources beyond their intended rights.
References
| Link | Resource |
|---|---|
| https://www.nagios.com/changelog/nagios-log-server-2024r1/ | Release Notes |
| https://www.vulncheck.com/advisories/nagios-log-server-incorrect-authorization-granting-full-api-access | Third Party Advisory |
Configurations
History
06 Nov 2025, 16:20
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 22:15
Updated : 2025-11-06 16:20
NVD link : CVE-2023-7322
Mitre link : CVE-2023-7322
CVE.ORG link : CVE-2023-7322
JSON object : View
Products Affected
nagios
- log_server
CWE
CWE-863
Incorrect Authorization
