host/servicegroup commands

Ethan Galstad egalstad at nagios.com
Tue Jul 26 03:26:29 CEST 2011


Patched - thanks!

Ethan Galstad

Sven Nierlein wrote:
> Hi,
> 
> One of our customers found a bug in the nagios cgis. It's easy to 
> reproduce:
> 
> 1. create a new user
> 2. give him authorized_for_all_services and authorized_for_all_hosts in 
> your cgi.cfg
> 
> The contact should now be able to see all hosts and services but should 
> not be allowed to submit any commands.
> However, if the contact submits hostgroup or servicegroup commands, they 
> are accepted and executed.
> The attached patch fixes that behavior.
> 
> Regards,
>   Sven
> 
> 
> ------------------------------------------------------------------------
> 
> ------------------------------------------------------------------------------
> All the data continuously generated in your IT infrastructure contains a 
> definitive record of customers, application performance, security 
> threats, fraudulent activity and more. Splunk takes this data and makes 
> sense of it. Business sense. IT sense. Common sense.. 
> http://p.sf.net/sfu/splunk-d2d-c1
> 
> 
> ------------------------------------------------------------------------
> 
> _______________________________________________
> Nagios-devel mailing list
> Nagios-devel at lists.sourceforge.net
> https://lists.sourceforge.net/lists/listinfo/nagios-devel

------------------------------------------------------------------------------
Magic Quadrant for Content-Aware Data Loss Prevention
Research study explores the data loss prevention market. Includes in-depth
analysis on the changes within the DLP market, and the criteria used to
evaluate the strengths and weaknesses of these DLP solutions.
http://www.accelacomm.com/jaw/sfnl/114/51385063/




More information about the Developers mailing list