CVE-2021-33178

The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:nagvis:nagvis:*:*:*:*:*:nagios_xi:*:*

History

29 Apr 2022, 13:12

Type Values Removed Values Added
References (MISC) https://nagvis.org/downloads/changelog/1.9.29 - (MISC) https://nagvis.org/downloads/changelog/1.9.29 - Release Notes, Vendor Advisory

21 Jan 2022, 19:15

Type Values Removed Values Added
Summary The Manage Backgrounds functionality within Nagvis versions prior to 2.0.9 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system. The Manage Backgrounds functionality within NagVis versions prior to 1.9.29 is vulnerable to an authenticated path traversal vulnerability. Exploitation of this results in a malicious actor having the ability to arbitrarily delete files on the local system.
References
  • (MISC) https://nagvis.org/downloads/changelog/1.9.29 -

21 Oct 2021, 14:31

Type Values Removed Values Added
CPE cpe:2.3:a:nagvis:nagvis:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
cpe:2.3:a:nagvis:nagvis:*:*:*:*:*:nagios_xi:*:*

20 Oct 2021, 18:26

Type Values Removed Values Added
CWE CWE-22
References (MISC) https://www.synopsys.com/blogs/software-security/cyrc-advisory-nagios-xi - (MISC) https://www.synopsys.com/blogs/software-security/cyrc-advisory-nagios-xi - Third Party Advisory
CPE cpe:2.3:a:nagvis:nagvis:*:*:*:*:*:*:*:*
cpe:2.3:a:nagios:nagios_xi:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 8.5
v3 : 6.5

14 Oct 2021, 15:25

Type Values Removed Values Added
New CVE

Information

Published : 2021-10-14 15:15

Updated : 2024-02-04 22:08


NVD link : CVE-2021-33178

Mitre link : CVE-2021-33178

CVE.ORG link : CVE-2021-33178


JSON object : View

Products Affected

nagvis

  • nagvis
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')