Security Advisory

CVE-2024-14006

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-10-30 21:38:42
Last updated 2025-11-17 18:21:49
Assigner VulnCheck
CVSS score 8.8
State PUBLISHED

Description

Nagios XI versions prior to 2024R1.2.2 contain a host header injection vulnerability. The application trusts the user-supplied HTTP Host header when constructing absolute URLs without sufficient validation. An unauthenticated, remote attacker can supply a crafted Host header to poison generated links or responses, which may facilitate phishing of credentials, account recovery link hijacking, and web cache poisoning.