CVE-2023-37154

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-37154
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-37154.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-37154
Aliases
  • GHSA-p3gv-vmpx-hhw4
Downstream
Published
2024-10-09T06:15:12Z
Modified
2025-10-16T09:59:37.334298Z
Severity
  • 8.4 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

checkbyssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

References

Affected packages

Git / github.com/nagios-plugins/nagios-plugins

Affected ranges

Type
GIT
Repo
https://github.com/nagios-plugins/nagios-plugins
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

r1_3_0-beta2
r1_3_0-beta3
r1_4-beta1
r1_4_0-alpha2
r1_4_0-alpha3

release-1.*

release-1.3.1
release-1.4
release-1.4.1
release-1.4.10
release-1.4.11
release-1.4.12
release-1.4.13
release-1.4.14
release-1.4.15
release-1.4.16
release-1.4.2
release-1.4.3
release-1.4.4
release-1.4.5
release-1.4.6
release-1.4.7
release-1.4.8
release-1.4.9
release-1.5

release-2.*

release-2.0
release-2.0.1
release-2.0.2
release-2.0.3
release-2.1.0
release-2.1.1
release-2.1.2
release-2.1.3
release-2.1.4
release-2.2.0
release-2.2.1
release-2.3.0
release-2.3.1
release-2.3.2
release-2.3.3
release-2.4.0
release-2.4.1
release-2.4.2
release-2.4.3
release-2.4.4

Database specific

vanir_signatures

[
    {
        "id": "CVE-2023-37154-96967795",
        "signature_version": "v1",
        "digest": {
            "length": 4281.0,
            "function_hash": "65435622679889613038174802112533940077"
        },
        "target": {
            "file": "plugins/check_by_ssh.c",
            "function": "process_arguments"
        },
        "deprecated": false,
        "signature_type": "Function",
        "source": "https://github.com/nagios-plugins/nagios-plugins/commit/e8810de21be80148562b7e0168b0a62aeedffde6"
    },
    {
        "id": "CVE-2023-37154-f29e0e4a",
        "signature_version": "v1",
        "digest": {
            "line_hashes": [
                "1764226779147952800252069985963470210",
                "29510619766522554077519892227178996097",
                "334559933293457597800218740066589645011",
                "73330748222578045117660887084600810860",
                "290319796360619242676652231027428424723",
                "59832891395856060679566955438359375680"
            ],
            "threshold": 0.9
        },
        "target": {
            "file": "plugins/check_by_ssh.c"
        },
        "deprecated": false,
        "signature_type": "Line",
        "source": "https://github.com/nagios-plugins/nagios-plugins/commit/e8810de21be80148562b7e0168b0a62aeedffde6"
    }
]