Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate sanitation or argument quoting, allowing an authenticated user with access to discovery functionality to execute arbitrary commands with the privileges of the application service.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | - | 2012 |
| nagios / nagios_xi | 2012-r1.0 | 2012-r1.0.x |
| nagios / nagios_xi | 2012-r1.1 | 2012-r1.1.x |
| nagios / nagios_xi | 2012-r1.2 | 2012-r1.2.x |
| nagios / nagios_xi | 2012-r1.3 | 2012-r1.3.x |
| nagios / nagios_xi | 2012-r1.4 | 2012-r1.4.x |
| nagios / nagios_xi | 2012-r1.5 | 2012-r1.5.x |