Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to poison generated links or responses, which may facilitate phishing of credentials, account recovery link hijacking, and web cache poisoning.
[
{
"events": [
{
"introduced": "0"
},
{
"fixed": "2024"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.0\\.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.0\\.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.1"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.1\\.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.2"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "2024-r1\\.2\\.1"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14006.json"