Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2024"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.0\\.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.0\\.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.2"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-13996.json"