Nagios Login page

This support forum board is for support questions relating to Nagios XI, our flagship commercial network monitoring solution.
Locked
sujitt
Posts: 132
Joined: Thu Apr 25, 2013 1:50 pm

Nagios Login page

Post by sujitt »

the forgot password feature on the nagios login page is very insecurely implemented. It gives way for anybody be able to reset the password of any user without verification.
Can we make this more secure or some way to protect admin passwords from being reset ?
abrist
Red Shirt
Posts: 8334
Joined: Thu Nov 15, 2012 1:20 pm

Re: Nagios Login page

Post by abrist »

Not necessarily insecure, but it definitely allows for vagrants to be rather annoying. I will open an internal bug fix for this. The email should probably give you a link to reset the password instead of the "Forgot Password" link resetting the password itself. Thanks for the heads up.
Former Nagios employee
"It is turtles. All. The. Way. Down. . . .and maybe an elephant or two."
VI VI VI - The editor of the Beast!
Come to the Dark Side.
cmerchant
Posts: 546
Joined: Wed Sep 24, 2014 11:19 am

Re: Nagios Login page

Post by cmerchant »

This fix was rolled into the source trunk and should be in the most recent version of Nagios XI.
Locked