Nagios
Log Server
Affected and fixed version statements observed in the public BlackTree CVE catalogue. These statements describe vulnerability scope, not publisher support entitlement.
This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.
A missing support date does not mean the product is supported. CVE publication dates and affected-version ranges must not be interpreted as EOL dates.
CVE-observed version history
| CVE | Published | Affected versions | Fixed version information | Publisher evidence |
|---|---|---|---|---|
| CVE-2025-34323 | 17 Nov 2025 | Log Server: < 2026R1.0.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-34322 | 17 Nov 2025 | Log Server: < 2026R1.0.1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7321 | 30 Oct 2025 | < 2.1.14 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2023-7323 | 30 Oct 2025 | < 2024R1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2020-36858 | 30 Oct 2025 | < 2.1.6 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-34298 | 30 Oct 2025 | Log Server: < 2024R1.3.2 | Nagios addresses this vulnerability as "Fixed a privilege escalation issue where a user can edit their own email and put in an invalid address." | Update reference ↗ |
| CVE-2025-34277 | 30 Oct 2025 | Log Server: < 2024R1.3.1 | Nagios addresses this vulnerability as "Nagios Log Server was vulnerable to remote code execution through malformed dashboard IDs" and "Fixed a security issue where Dashboard ID values were not checked before being sent to the API." | Update reference ↗ |
| CVE-2025-34272 | 30 Oct 2025 | Log Server: < 2024R2.0.3 | Nagios addresses this vulnerability as "Use the empty dashboard as the default if a user’s default dashboard has been deleted" and "Use the empty dashboard as the default if a user’s default dashboard has been deleted." | Update reference ↗ |
| CVE-2025-34273 | 30 Oct 2025 | Log Server: < 2024R2.0.3 | Nagios addresses this vulnerability as "Non-admin users can no longer delete global dashboards" and "Non-admin users can no longer delete global dashboards." | Update reference ↗ |
| CVE-2024-58273 | 30 Oct 2025 | Log Server: < 2024R1.0.2 | Nagios addresses this vulnerablity as "Nagios Log Server was vulnerable to a privilege escalation from the Apache shell user to root and from the backend shell user to root" and "Fixed a privilege escalation vulnerability in several backend scripts." | Update reference ↗ |
| CVE-2025-34274 | 30 Oct 2025 | Log Server: < 2024R2.0.3 | Nagios addresses this vulnerability as "Changed Logstash process to run as the nagios user instead of root." | Update reference ↗ |
| CVE-2023-7322 | 30 Oct 2025 | < 2024R1 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2016-15049 | 30 Oct 2025 | < 1.4.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-34271 | 30 Oct 2025 | Log Server: < 2024R2.0.2 | Nagios addresses this vulnerability as "There was an issue in Nagios Log Server where requests for credentials from a cluster manager would not use SSL, even if SSL was enabled" and "Fixed issue with requesting credentials from a cluster manager wouldn’t use SSL if enabled." | Update reference ↗ |
| CVE-2025-34270 | 30 Oct 2025 | Log Server: < 2024R2.0.2 | Nagios addresses this vulnerability as "There was an issue in Nagios Log Server where the password field was not properly obfuscated when importing AD/LDAP users" and "Fixed issue where the password field was not properly obfuscated when importing AD/LDAP users." | Update reference ↗ |
| CVE-2025-44824 | 7 Oct 2025 | < 2024R1.3.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
| CVE-2025-44823 | 7 Oct 2025 | < 2024R1.3.2 | No fixed version is explicitly recorded in the structured CVE data. | Use CVE record |
How this record is maintained
The CVE inventory is reconciled automatically from cve.blacktree.nl. Exact identity matches link to existing Lifecycle product or package histories. Unmatched products stay in a prioritised publisher-source research queue, and Lifecycle marks the date gap instead of inferring a support boundary from vulnerability data.