{"api_version":"v1","generated_at":"2026-10-08T10:00:00+00:00","product":{"cve_count":17,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-nagios-log-server-d947c1787d66","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Log Server","next_cursor":null,"observations":[{"affected":"Log Server: < 2026R1.0.1","affected_versions_present":true,"cve_id":"CVE-2025-34323","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34323","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T02:08:14.839Z","patch_url":"","primary_source":"","published":"2025-11-17T17:48:28.973Z"},{"affected":"Log Server: < 2026R1.0.1","affected_versions_present":true,"cve_id":"CVE-2025-34322","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34322","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-05-14T02:08:14.110Z","patch_url":"","primary_source":"","published":"2025-11-17T17:48:04.503Z"},{"affected":"< 2.1.14","affected_versions_present":true,"cve_id":"CVE-2023-7321","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-7321","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-17T21:36:23.480Z","patch_url":"","primary_source":"","published":"2025-10-30T21:27:23.232Z"},{"affected":"< 2024R1","affected_versions_present":true,"cve_id":"CVE-2023-7323","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-7323","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-17T21:36:23.836Z","patch_url":"","primary_source":"","published":"2025-10-30T21:27:03.493Z"},{"affected":"< 2.1.6","affected_versions_present":true,"cve_id":"CVE-2020-36858","cve_url":"https://cve.blacktree.nl/cve/CVE-2020-36858","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-17T21:36:22.598Z","patch_url":"","primary_source":"","published":"2025-10-30T21:26:38.984Z"},{"affected":"Log Server: < 2024R1.3.2","affected_versions_present":true,"cve_id":"CVE-2025-34298","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34298","fixed":"Nagios addresses this vulnerability as \"Fixed a privilege escalation issue where a user can edit their own email and put in an invalid address.\"","last_modified":"2025-11-17T21:36:25.925Z","patch_url":"https://www.nagios.com/changelog/nagios-log-server-2024r1/","primary_source":"","published":"2025-10-30T21:25:52.056Z"},{"affected":"Log Server: < 2024R1.3.1","affected_versions_present":true,"cve_id":"CVE-2025-34277","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34277","fixed":"Nagios addresses this vulnerability as \"Nagios Log Server was vulnerable to remote code execution through malformed dashboard IDs\" and \"Fixed a security issue where Dashboard ID values were not checked before being sent to the API.\"","last_modified":"2025-11-17T21:36:25.444Z","patch_url":"https://www.nagios.com/products/security/#log-server","primary_source":"","published":"2025-10-30T21:25:32.852Z"},{"affected":"Log Server: < 2024R2.0.3","affected_versions_present":true,"cve_id":"CVE-2025-34272","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34272","fixed":"Nagios addresses this vulnerability as \"Use the empty dashboard as the default if a user\u2019s default dashboard has been deleted\" and \"Use the empty dashboard as the default if a user\u2019s default dashboard has been deleted.\"","last_modified":"2025-11-17T21:36:24.794Z","patch_url":"https://www.nagios.com/products/security/#log-server-2024R2","primary_source":"","published":"2025-10-30T21:25:10.601Z"},{"affected":"Log Server: < 2024R2.0.3","affected_versions_present":true,"cve_id":"CVE-2025-34273","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34273","fixed":"Nagios addresses this vulnerability as \"Non-admin users can no longer delete global dashboards\" and \"Non-admin users can no longer delete global dashboards.\"","last_modified":"2025-11-17T21:36:24.971Z","patch_url":"https://www.nagios.com/products/security/#log-server-2024R2","primary_source":"","published":"2025-10-30T21:24:43.451Z"},{"affected":"Log Server: < 2024R1.0.2","affected_versions_present":true,"cve_id":"CVE-2024-58273","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-58273","fixed":"Nagios addresses this vulnerablity as \"Nagios Log Server was vulnerable to a privilege escalation from the Apache shell user to root and from the backend shell user to root\" and \"Fixed a privilege escalation vulnerability in several backend scripts.\"","last_modified":"2025-11-17T21:36:24.008Z","patch_url":"https://www.nagios.com/products/security/#log-server","primary_source":"","published":"2025-10-30T21:24:15.621Z"},{"affected":"Log Server: < 2024R2.0.3","affected_versions_present":true,"cve_id":"CVE-2025-34274","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34274","fixed":"Nagios addresses this vulnerability as \"Changed Logstash process to run as the nagios user instead of root.\"","last_modified":"2025-11-17T21:36:25.216Z","patch_url":"https://www.nagios.com/products/security/#log-server-2024R2","primary_source":"","published":"2025-10-30T21:23:54.741Z"},{"affected":"< 2024R1","affected_versions_present":true,"cve_id":"CVE-2023-7322","cve_url":"https://cve.blacktree.nl/cve/CVE-2023-7322","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-17T21:36:23.640Z","patch_url":"","primary_source":"","published":"2025-10-30T21:23:34.547Z"},{"affected":"< 1.4.2","affected_versions_present":true,"cve_id":"CVE-2016-15049","cve_url":"https://cve.blacktree.nl/cve/CVE-2016-15049","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-11-17T21:36:22.045Z","patch_url":"","primary_source":"","published":"2025-10-30T21:23:13.241Z"},{"affected":"Log Server: < 2024R2.0.2","affected_versions_present":true,"cve_id":"CVE-2025-34271","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34271","fixed":"Nagios addresses this vulnerability as \"There was an issue in Nagios Log Server where requests for credentials from a cluster manager would not use SSL, even if SSL was enabled\" and \"Fixed issue with requesting credentials from a cluster manager wouldn\u2019t use SSL if enabled.\"","last_modified":"2025-11-17T21:36:24.505Z","patch_url":"https://www.nagios.com/products/security/#log-server-2024R2","primary_source":"","published":"2025-10-30T21:22:51.043Z"},{"affected":"Log Server: < 2024R2.0.2","affected_versions_present":true,"cve_id":"CVE-2025-34270","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-34270","fixed":"Nagios addresses this vulnerability as \"There was an issue in Nagios Log Server where the password field was not properly obfuscated when importing AD/LDAP users\" and \"Fixed issue where the password field was not properly obfuscated when importing AD/LDAP users.\"","last_modified":"2025-11-17T21:36:24.190Z","patch_url":"https://www.nagios.com/products/security/#log-server-2024R2","primary_source":"","published":"2025-10-30T21:22:28.949Z"},{"affected":"< 2024R1.3.2","affected_versions_present":true,"cve_id":"CVE-2025-44824","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-44824","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-08T17:23:59.563Z","patch_url":"","primary_source":"","published":"2025-10-07T00:00:00.000Z"},{"affected":"< 2024R1.3.2","affected_versions_present":true,"cve_id":"CVE-2025-44823","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-44823","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-10-07T20:45:38.583Z","patch_url":"","primary_source":"","published":"2025-10-07T00:00:00.000Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Nagios"}}
