Description
Nagios XI versions prior to 2024R1.1.3 did not invalidate all other active sessions for a user when that user's password was changed. As a result, any pre-existing sessions (including those potentially controlled by an attacker) remained valid after a credential update. This insufficient session expiration could allow continued unauthorized access to user data and actions even after a password change.
Problem types
CWE-613 Insufficient Session Expiration
Product status
Any version before 2024R1.1.3
Credits
Jack Eli
References
www.nagios.com/products/security/
www.nagios.com/changelog/nagios-xi/
www.vulncheck.com/...n-not-invalidated-after-password-change