NagiosXI User Identity Usurped by Acknowledgement URL
Posted: Tue Aug 27, 2013 1:40 pm
Hello,
First, it is my understanding that the URL that in an alert/notification email is user specific. If a recipient uses that URL to acknowledge an alert, it is marked as acknowledged by that user. This leads into my second question and area of concern.
One of our users forwarded an email to me that he had received from Nagios. I clicked on his URL and, without providing credentials of any kind, became that user in the NagiosXI interface. This raises obvious security concerns that we would like to quantify before moving forward with our implementation. Under what conditions can/should that ever happen? Is it possible a user could usurp the identity of a higher privileged user by obtaining one of their acknowledgement URL's ?
Please let me know if you have questions about any specifics...
thank you,
Clint
First, it is my understanding that the URL that in an alert/notification email is user specific. If a recipient uses that URL to acknowledge an alert, it is marked as acknowledged by that user. This leads into my second question and area of concern.
One of our users forwarded an email to me that he had received from Nagios. I clicked on his URL and, without providing credentials of any kind, became that user in the NagiosXI interface. This raises obvious security concerns that we would like to quantify before moving forward with our implementation. Under what conditions can/should that ever happen? Is it possible a user could usurp the identity of a higher privileged user by obtaining one of their acknowledgement URL's ?
Please let me know if you have questions about any specifics...
thank you,
Clint