N
agios Log Server versions prior to 2024R1 contain an incorrect authorization vulnerability. Users who lacked the required API permission were nevertheless able to invoke API endpoints, resulting in unintended access to data and actions exposed via the API. This incorrect authorization check could allow authenticated but non-privileged users to read or modify resources beyond their intended rights.
References
| Link | Resource |
|---|---|
| https://www.nagios.com/changelog/nagios-log-server-2024r1/ | Release Notes |
| https://www.vulncheck.com/advisories/nagios-log-server-incorrect-authorization-granting-full-api-access | Third Party Advisory |
Configurations
History
06 Nov 2025, 16:20
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Nagios
Nagios log Server |
|
| References | () https://www.nagios.com/changelog/nagios-log-server-2024r1/ - Release Notes | |
| References | () https://www.vulncheck.com/advisories/nagios-log-server-incorrect-authorization-granting-full-api-access - Third Party Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| CPE | cpe:2.3:a:nagios:log_server:*:*:*:*:*:*:*:* |
30 Oct 2025, 22:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-10-30 22:15
Updated : 2025-11-06 16:20
NVD link : CVE-2023-7322
Mitre link : CVE-2023-7322
CVE.ORG link : CVE-2023-7322
JSON object : View
Products Affected
CWE
CWE-863
Incorrect Authorization