Nagios NRPE 3.2.1 has Insufficient Filtering because, for example, nasty_metachars interprets n as the character and the character n (not as the n newline sequence). This can cause command injection.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Remote_plug_in_executor | Nagios | 3.2.1 (including) | 3.2.1 (including) |
Nagios-nrpe | Ubuntu | bionic | * |
Nagios-nrpe | Ubuntu | eoan | * |
Nagios-nrpe | Ubuntu | esm-apps/bionic | * |
Nagios-nrpe | Ubuntu | trusty | * |
Nagios-nrpe | Ubuntu | upstream | * |