checkbyssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
{
"binaries": [
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "monitoring-plugins-standard"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "nagios-plugins"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "nagios-plugins-basic"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "nagios-plugins-common"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "nagios-plugins-extra"
},
{
"binary_version": "2.1.2-2ubuntu2",
"binary_name": "nagios-plugins-standard"
}
]
}{
"binaries": [
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "monitoring-plugins-standard"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "nagios-plugins"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "nagios-plugins-basic"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "nagios-plugins-common"
},
{
"binary_version": "2.2-3ubuntu3.18.04.1",
"binary_name": "nagios-plugins-standard"
}
]
}{
"binaries": [
{
"binary_version": "2.2-6ubuntu1.2",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.2-6ubuntu1.2",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.2-6ubuntu1.2",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.2-6ubuntu1.2",
"binary_name": "monitoring-plugins-standard"
}
]
}{
"binaries": [
{
"binary_version": "2.3.1-1ubuntu4",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.3.1-1ubuntu4",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.3.1-1ubuntu4",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.3.1-1ubuntu4",
"binary_name": "monitoring-plugins-standard"
}
]
}{
"binaries": [
{
"binary_version": "2.3.5-1ubuntu3",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.3.5-1ubuntu3",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.3.5-1ubuntu3",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.3.5-1ubuntu3",
"binary_name": "monitoring-plugins-standard"
}
]
}{
"binaries": [
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins-standard"
}
]
}{
"binaries": [
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins"
},
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins-basic"
},
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins-common"
},
{
"binary_version": "2.4.0-1ubuntu1",
"binary_name": "monitoring-plugins-standard"
}
]
}