Event Log permission issue/ Multitenancy broken

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
User avatar
arnab.roy
Posts: 354
Joined: Sat Apr 30, 2011 10:24 am

Event Log permission issue/ Multitenancy broken

Post by arnab.roy »

Hi ,

I have found that when a contact(non-admin), which can see only one host for e.g can actually see events from all hosts when the user clicks on the event log. This has put is in serious pickle as one customer can see another customers sensitive information!!!!!!! Can somebody get back to me with priority fix please.

Thanks
Arnab
scottwilkerson
DevOps Engineer
Posts: 19396
Joined: Tue Nov 15, 2011 3:11 pm
Location: Nagios Enterprises
Contact:

Re: Event Log permission issue/ Multitenancy broken

Post by scottwilkerson »

I couldn't reproduce this..

What version of XI is this on?
What Authorization Level items are checked for the user that can see the event log?
Former Nagios employee
Creator:
Human Design Website
Get Your Human Design Chart
User avatar
arnab.roy
Posts: 354
Joined: Sat Apr 30, 2011 10:24 am

Re: Event Log permission issue/ Multitenancy broken

Post by arnab.roy »

Hi Scott,

This is running XI 2011r2.4, Auth Level is set to user and permission is set to read-only. All other elements behaves fine, unfortunately I am unable to reproduce this either as I just checked up and logged in as that user and it doesnt show the Monitoring Process Category on the left hand nav bar. Odd! I will keep an eye out if I can see this again.

Thanks for looking at it anyways.

Cheers
Arnab
Locked