Vulnerability CVE-2023-37154


Published: 2024-10-09

Description:
check_by_ssh in Nagios nagios-plugins 2.4.5 allows arbitrary command execution via ProxyCommand, LocalCommand, and PermitLocalCommand with \${IFS}. This has been categorized both as fixed in e8810de, and as intended behavior.

 References:
https://github.com/nagios-plugins/nagios-plugins/commit/e8810de21be80148562b7e0168b0a62aeedffde6
https://github.com/monitoring-plugins/monitoring-plugins/security/advisories/GHSA-p3gv-vmpx-hhw4
https://joshua.hu/nagios-hacking-cve-2023-37154

Copyright 2026, cxsecurity.com

 

Back to Top