Page 1 of 1

Security Issue: Nagios Core - Performance Graphs Using Influ

Posted: Tue Aug 10, 2021 9:57 am
by marcosjr83
Hi,

The article Nagios Core - Performance Graphs Using InfluxDB + Nagflux + Grafana + Histou (https://support.nagios.com/kb/article/n ... lux_Config), have a critical security issue. When you install InfluxDB in a host with public IP without configure authentication (https://docs.influxdata.com/influxdb/v1 ... orization/): anybody in anywhere can access Influx database with one command (influx -host "IP or hostname"). Locally anybody in the network do the same. I'm tested this, my server had this issue.

Re: Security Issue: Nagios Core - Performance Graphs Using I

Posted: Wed Aug 11, 2021 6:30 am
by mcapra
I'd suggest shooting an email to security@nagios.com.

https://www.nagios.com/products/security/

I think a simple disclaimer at the top of the docs to the effect of "don't do this in prod, it exposes your influxdb instance to anything with a network connection" would go a long way.