GPU VulnDB

Database/Control plane, storage & DevOps

Nagios XI: Docker Wizard command injection gives admins code execution as the web user

CVSS 9.4CVE-2024-14005Control plane, storage & DevOpscurated

Impact

Input to the Docker Wizard is passed into backend command invocations without filtering shell metacharacters, so an authenticated administrator turns a configuration form into arbitrary commands running as the Nagios XI web user. A monitoring server is a high-value pivot: it holds check credentials, SSH keys and SNMP communities for much of the fleet, and it is reachable from everything it monitors. The privilege bar is the mitigating factor - this is an admin-to-shell escalation, not an unauthenticated break-in - so the realistic threat models are a stolen or shared admin session and an operator account that should not have had host-level reach.

Who can reach it

An authenticated Nagios XI administrator using the Docker Wizard in the web UI. Admin privileges are required; no exploitation is possible from an unauthenticated position.

What to do

Upgrade Nagios XI to 2024R1.2 or later, per the vendor changelog. This is a web application upgrade on the monitoring host - the Nagios services restart and checks gap briefly; no fleet nodes are touched. Where an upgrade has to wait, treat Nagios XI admin as equivalent to shell on the monitoring host: trim the admin list, put the UI behind SSO, and rotate the credentials the monitoring server stores for the fleet if any admin account is in doubt.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.