Improper neutralization of input in Nagvis before version 1.9.47 which can lead to livestatus injection
References
Link | Resource |
---|---|
https://github.com/NagVis/nagvis/pull/398/commits/8d5d07e22dfca78df7420ac81cffff6f45ca9694 | Patch |
https://www.nagvis.org/downloads/changelog/1.9.47 | Release Notes |
Configurations
History
21 Aug 2025, 22:15
Type | Values Removed | Values Added |
---|---|---|
First Time |
Nagvis
Nagvis nagvis |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
CPE | cpe:2.3:a:nagvis:nagvis:*:*:*:*:*:*:*:* | |
References | () https://github.com/NagVis/nagvis/pull/398/commits/8d5d07e22dfca78df7420ac81cffff6f45ca9694 - Patch | |
References | () https://www.nagvis.org/downloads/changelog/1.9.47 - Release Notes |
28 May 2025, 15:01
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
27 May 2025, 07:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-27 07:15
Updated : 2025-08-21 22:15
NVD link : CVE-2024-38866
Mitre link : CVE-2024-38866
CVE.ORG link : CVE-2024-38866
JSON object : View
Products Affected
nagvis
- nagvis
CWE
CWE-140
Improper Neutralization of Delimiters