checkbyssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.
{
"binaries": [
{
"binary_name": "monitoring-plugins",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "monitoring-plugins-basic",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "monitoring-plugins-common",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "monitoring-plugins-standard",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "nagios-plugins",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "nagios-plugins-basic",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "nagios-plugins-common",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "nagios-plugins-extra",
"binary_version": "2.1.2-2ubuntu2"
},
{
"binary_name": "nagios-plugins-standard",
"binary_version": "2.1.2-2ubuntu2"
}
]
}{
"binaries": [
{
"binary_name": "monitoring-plugins",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "monitoring-plugins-basic",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "monitoring-plugins-common",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "monitoring-plugins-standard",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "nagios-plugins",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "nagios-plugins-basic",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "nagios-plugins-common",
"binary_version": "2.2-3ubuntu3.18.04.1"
},
{
"binary_name": "nagios-plugins-standard",
"binary_version": "2.2-3ubuntu3.18.04.1"
}
]
}{
"binaries": [
{
"binary_name": "monitoring-plugins",
"binary_version": "2.2-6ubuntu1.2"
},
{
"binary_name": "monitoring-plugins-basic",
"binary_version": "2.2-6ubuntu1.2"
},
{
"binary_name": "monitoring-plugins-common",
"binary_version": "2.2-6ubuntu1.2"
},
{
"binary_name": "monitoring-plugins-standard",
"binary_version": "2.2-6ubuntu1.2"
}
]
}{
"binaries": [
{
"binary_name": "monitoring-plugins",
"binary_version": "2.3.1-1ubuntu4"
},
{
"binary_name": "monitoring-plugins-basic",
"binary_version": "2.3.1-1ubuntu4"
},
{
"binary_name": "monitoring-plugins-common",
"binary_version": "2.3.1-1ubuntu4"
},
{
"binary_name": "monitoring-plugins-standard",
"binary_version": "2.3.1-1ubuntu4"
}
]
}{
"binaries": [
{
"binary_name": "monitoring-plugins",
"binary_version": "2.3.5-1ubuntu3"
},
{
"binary_name": "monitoring-plugins-basic",
"binary_version": "2.3.5-1ubuntu3"
},
{
"binary_name": "monitoring-plugins-common",
"binary_version": "2.3.5-1ubuntu3"
},
{
"binary_name": "monitoring-plugins-standard",
"binary_version": "2.3.5-1ubuntu3"
}
]
}{
"binaries": [
{
"binary_name": "monitoring-plugins",
"binary_version": "2.4.0-1ubuntu1"
},
{
"binary_name": "monitoring-plugins-basic",
"binary_version": "2.4.0-1ubuntu1"
},
{
"binary_name": "monitoring-plugins-common",
"binary_version": "2.4.0-1ubuntu1"
},
{
"binary_name": "monitoring-plugins-standard",
"binary_version": "2.4.0-1ubuntu1"
}
]
}