CVE-2023-37154

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-37154
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-37154.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-37154
Aliases
  • GHSA-p3gv-vmpx-hhw4
Related
Published
2024-10-09T06:15:12Z
Modified
2024-10-12T10:59:41.687039Z
Summary
[none]
Details

checkbyssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

References

Affected packages

Debian:11 / monitoring-plugins

Package

Name
monitoring-plugins
Purl
pkg:deb/debian/monitoring-plugins?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.1-1
2.3.2-1
2.3.2-2
2.3.2-3
2.3.3-1
2.3.3-2~bpo11+1
2.3.3-2
2.3.3-3
2.3.3-4
2.3.3-5~bpo11+1
2.3.3-5
2.3.3-6
2.3.5-1
2.4.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:12 / monitoring-plugins

Package

Name
monitoring-plugins
Purl
pkg:deb/debian/monitoring-plugins?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.3-5
2.3.3-5+deb12u1
2.3.3-5+deb12u2
2.3.3-6
2.3.5-1
2.4.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Debian:13 / monitoring-plugins

Package

Name
monitoring-plugins
Purl
pkg:deb/debian/monitoring-plugins?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*

2.3.3-5
2.3.3-6
2.3.5-1
2.4.0-1

Ecosystem specific

{
    "urgency": "unimportant"
}

Git / github.com/nagios-plugins/nagios-plugins

Affected ranges

Type
GIT
Repo
https://github.com/nagios-plugins/nagios-plugins
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Other

r1_3_0-beta2
r1_3_0-beta3
r1_4-beta1
r1_4_0-alpha2
r1_4_0-alpha3

release-1.*

release-1.3.1
release-1.4
release-1.4.1
release-1.4.10
release-1.4.11
release-1.4.12
release-1.4.13
release-1.4.14
release-1.4.15
release-1.4.16
release-1.4.2
release-1.4.3
release-1.4.4
release-1.4.5
release-1.4.6
release-1.4.7
release-1.4.8
release-1.4.9
release-1.5

release-2.*

release-2.0
release-2.0.1
release-2.0.2
release-2.0.3
release-2.1.0
release-2.1.1
release-2.1.2
release-2.1.3
release-2.1.4
release-2.2.0
release-2.2.1
release-2.3.0
release-2.3.1
release-2.3.2
release-2.3.3
release-2.4.0
release-2.4.1
release-2.4.2
release-2.4.3
release-2.4.4