CVE-2020-13977: Fedoraproject Fedora
Medium severity, CVSS 4.9. EPSS: 2.7% chance of exploitation in the next 30 days.
Nagios 4.4.5 allows an attacker, who already has administrative access to change the "URL for JSON CGIs" configuration setting, to modify the Alert Histogram and Trends code via crafted versions of the archivejson.cgi, objectjson.cgi, and statusjson.cgi files. NOTE: this vulnerability has been mistakenly associated with CVE-2020-1408.
Affected products
- Fedoraproject Fedora: version 32 only; version 33 only; version 34 only
- Nagios Nagios: version 4.4.5 only
Published 2020-06-09. Last modified 2026-06-17.