Description
Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing unintended access to discovery operations.
Problem types
Product status
Any version before 2012R1.6
Credits
James Clawson
References
www.nagios.com/changelog/nagios-xi/
www.vulncheck.com/...xi-auto-discovery-missing-authorization