Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to poison generated links or responses, which may facilitate phishing of credentials, account recovery link hijacking, and web cache poisoning.
| Software | From | Fixed in |
|---|---|---|
| nagios / nagios_xi | - | 2024 |
| nagios / nagios_xi | 2024-r1 | 2024-r1.x |
| nagios / nagios_xi | 2024-r1.0.1 | 2024-r1.0.1.x |
| nagios / nagios_xi | 2024-r1.0.2 | 2024-r1.0.2.x |
| nagios / nagios_xi | 2024-r1.1 | 2024-r1.1.x |
| nagios / nagios_xi | 2024-r1.1.1 | 2024-r1.1.1.x |
| nagios / nagios_xi | 2024-r1.1.2 | 2024-r1.1.2.x |
| nagios / nagios_xi | 2024-r1.1.3 | 2024-r1.1.3.x |
| nagios / nagios_xi | 2024-r1.1.4 | 2024-r1.1.4.x |
| nagios / nagios_xi | 2024-r1.1.5 | 2024-r1.1.5.x |
| nagios / nagios_xi | 2024-r1.2 | 2024-r1.2.x |
| nagios / nagios_xi | 2024-r1.2.1 | 2024-r1.2.1.x |