📦 Log Server

by Nagios

🔍 What is Log Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-34274

CRITICAL CVSS 9.8 Oct 30, 2025

Nagios Log Server versions before 2024R2.0.3 run the embedded Logstash process with root privileges, creating a privilege escalation vulnerability. If an attacker compromises Logstash through insecure...

CVE-2025-34271

CRITICAL CVSS 9.8 Oct 30, 2025

Nagios Log Server versions before 2024R2.0.2 transmit cluster credentials over unencrypted channels even when SSL/TLS is configured, allowing network-positioned attackers to intercept authentication c...

CVE-2025-44823

CRITICAL CVSS 9.9 Oct 7, 2025

Nagios Log Server before version 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a specific API endpoint. This vulnerability affects all Nagios Log Server insta...

CVE-2025-34322

HIGH CVSS 7.2 Nov 17, 2025

Nagios Log Server versions before 2026R1.0.1 contain an authenticated command injection vulnerability in the experimental 'Natural Language Queries' feature. Authenticated users with access to Global ...

CVE-2025-34323

HIGH CVSS 7.8 Nov 17, 2025

This CVE describes a local privilege escalation vulnerability in Nagios Log Server where the 'www-data' user can replace root-owned scripts in a writable directory and execute them via sudo without a ...

CVE-2024-58273

HIGH CVSS 7.8 Oct 30, 2025

Nagios Log Server versions before 2024R1.0.2 contain a local privilege escalation vulnerability. An attacker who can execute commands as the Apache web user or backend shell user can escalate privileg...

CVE-2023-7322

HIGH CVSS 8.1 Oct 30, 2025

Nagios Log Server versions before 2024R1 have an incorrect authorization vulnerability where authenticated users without proper API permissions can access API endpoints they shouldn't. This allows non...

CVE-2025-29471

HIGH CVSS 8.3 Apr 15, 2025

A Cross-Site Scripting (XSS) vulnerability in Nagios Log Server v.2024R1.3.1 allows remote attackers to inject malicious scripts via the Email field. This could enable attackers to execute arbitrary c...

CVE-2025-34270

MEDIUM CVSS 4.9 Oct 30, 2025

Nagios Log Server versions before 2024R2.0.2 expose plaintext AD/LDAP passwords during user import operations. This allows administrators or users with access to import results to view sensitive crede...

CVE-2025-34273

MEDIUM CVSS 6.5 Oct 30, 2025

Nagios Log Server versions before 2024R2.0.3 have an authorization flaw that lets non-admin users delete global dashboards. This affects all organizations using vulnerable Nagios Log Server instances ...

CVE-2023-7321

MEDIUM CVSS 5.4 Oct 30, 2025

Nagios Log Server versions before 2.1.14 contain a stored cross-site scripting vulnerability in the Snapshots Page. Attackers can inject malicious scripts into log data that execute in victims' browse...

CVE-2020-36858

MEDIUM CVSS 5.4 Oct 30, 2025

This cross-site scripting (XSS) vulnerability in Nagios Log Server allows attackers to inject malicious scripts into web pages when users interact with Create User, Edit User, or Manage Host Lists fun...

CVE-2016-15049

MEDIUM CVSS 5.4 Oct 30, 2025

Nagios Log Server versions before 1.4.2 contain a cross-site scripting vulnerability in the Dashboards section. When viewing log entries in the Logs table, malicious script content from logs can execu...