Vulnerability Description
Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injection.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nagios | Remote Plug In Executor | 3.2.1 |
| Fedoraproject | Fedora | 32 |
References
- https://herolab.usd.de/security-advisories/Third Party Advisory
- https://herolab.usd.de/security-advisories/usd-2020-0002/ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://herolab.usd.de/security-advisories/Third Party Advisory
- https://herolab.usd.de/security-advisories/usd-2020-0002/ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
FAQ
What is CVE-2020-6581?
CVE-2020-6581 is a vulnerability with a CVSS score of 7.3 (HIGH). Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets \n as the character \ and the character n (not as the \n newline sequence). This can cause command injecti...
How severe is CVE-2020-6581?
CVE-2020-6581 has been rated HIGH with a CVSS base score of 7.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-6581?
Check the references section above for vendor advisories and patch information. Affected products include: Nagios Remote Plug In Executor, Fedoraproject Fedora.