CVE Vulnerabilities

CVE-2025-34270

Cleartext Storage of Sensitive Information

Published: Oct 30, 2025 | Modified: Nov 06, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

NameVendorStart VersionEnd Version
Log_serverNagios*2024 (excluding)
Log_serverNagios2024-r1 (including)2024-r1 (including)
Log_serverNagios2024-r1.0.1 (including)2024-r1.0.1 (including)
Log_serverNagios2024-r1.0.2 (including)2024-r1.0.2 (including)
Log_serverNagios2024-r1.1 (including)2024-r1.1 (including)
Log_serverNagios2024-r1.2 (including)2024-r1.2 (including)
Log_serverNagios2024-r1.3 (including)2024-r1.3 (including)
Log_serverNagios2024-r1.3.1 (including)2024-r1.3.1 (including)
Log_serverNagios2024-r1.3.2 (including)2024-r1.3.2 (including)
Log_serverNagios2024-r1.3.3 (including)2024-r1.3.3 (including)
Log_serverNagios2024-r1.3.4 (including)2024-r1.3.4 (including)
Log_serverNagios2024-r1.3.5 (including)2024-r1.3.5 (including)
Log_serverNagios2024-r2 (including)2024-r2 (including)
Log_serverNagios2024-r2.0.1 (including)2024-r2.0.1 (including)

Potential Mitigations

References