Nagios XI versions prior to 2024R1.1.3, under certain circumstances, disclose the server's Active Directory (AD) or LDAP authentication token to an authenticated user. Exposure of the server’s AD/LDAP token could allow domain-wide authentication misuse, escalation of privileges, or further compromise of network-integrated systems.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | - | 2024 |
| nagios / nagios_xi | 2024-r1 | 2024-r1.x |
| nagios / nagios_xi | 2024-r1.0.1 | 2024-r1.0.1.x |
| nagios / nagios_xi | 2024-r1.0.2 | 2024-r1.0.2.x |
| nagios / nagios_xi | 2024-r1.1 | 2024-r1.1.x |
| nagios / nagios_xi | 2024-r1.1.1 | 2024-r1.1.1.x |
| nagios / nagios_xi | 2024-r1.1.2 | 2024-r1.1.2.x |