Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
History

Fri, 31 Oct 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nagios
Nagios xi
Vendors & Products Nagios
Nagios xi

Thu, 30 Oct 2025 21:30:00 +0000

Type Values Removed Values Added
Description Nagios XI versions prior to 2024R1.4.2 revealed API keys to users who were not authorized for API access when using Neptune themes. An authenticated user without API privileges could view another user's or their own API key value.
Title Nagios XI < 2024R1.4.2 API Key Disclosure via Neptune Themes
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2025-10-30T21:29:37.293Z

Updated: 2025-10-31T15:06:58.704Z

Reserved: 2025-04-15T19:15:22.581Z

Link: CVE-2025-34283

cve-icon Vulnrichment

Updated: 2025-10-31T15:06:54.556Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-10-30T22:15:48.633

Modified: 2025-11-04T15:41:56.843

Link: CVE-2025-34283

cve-icon Redhat

No data.