Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpoints and pages that should require elevated permissions, exposing discovery results and allowing unintended access to discovery operations.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | - | 2011.x |
| nagios / nagios_xi | 2012-r1.0 | 2012-r1.0.x |
| nagios / nagios_xi | 2012-r1.1 | 2012-r1.1.x |
| nagios / nagios_xi | 2012-r1.2 | 2012-r1.2.x |
| nagios / nagios_xi | 2012-r1.3 | 2012-r1.3.x |
| nagios / nagios_xi | 2012-r1.4 | 2012-r1.4.x |
| nagios / nagios_xi | 2012-r1.5 | 2012-r1.5.x |