CVE Vulnerabilities

CVE-2025-34270

Cleartext Storage of Sensitive Information

Published: Oct 30, 2025 | Modified: Nov 06, 2025
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Nagios Log Server versions prior to 2024R2.0.2 contain a vulnerability in the AD/LDAP user import functionality as it fails to obfuscate the password field during import. As a result, the plaintext password supplied for imported accounts may be exposed in the user interface, logs, or other diagnostic output. This can leak sensitive credentials to administrators or anyone with access to import results.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Log_server Nagios * 2024 (excluding)
Log_server Nagios 2024-r1 (including) 2024-r1 (including)
Log_server Nagios 2024-r1.0.1 (including) 2024-r1.0.1 (including)
Log_server Nagios 2024-r1.0.2 (including) 2024-r1.0.2 (including)
Log_server Nagios 2024-r1.1 (including) 2024-r1.1 (including)
Log_server Nagios 2024-r1.2 (including) 2024-r1.2 (including)
Log_server Nagios 2024-r1.3 (including) 2024-r1.3 (including)
Log_server Nagios 2024-r1.3.1 (including) 2024-r1.3.1 (including)
Log_server Nagios 2024-r1.3.2 (including) 2024-r1.3.2 (including)
Log_server Nagios 2024-r1.3.3 (including) 2024-r1.3.3 (including)
Log_server Nagios 2024-r1.3.4 (including) 2024-r1.3.4 (including)
Log_server Nagios 2024-r1.3.5 (including) 2024-r1.3.5 (including)
Log_server Nagios 2024-r2 (including) 2024-r2 (including)
Log_server Nagios 2024-r2.0.1 (including) 2024-r2.0.1 (including)

Potential Mitigations

References