Linuxfabrik monitoring-plugins provides Python monitoring plugins for Icinga, Nagios, and related monitoring systems. In 6.0.0 and earlier, the redfish-* plugins built request URLs by concatenating an operator-supplied base URL with response-supplied @odata.id links, allowing a malicious or compromised BMC to redirect authenticated Redfish requests and disclose X-Auth-Token or HTTP Basic credentials.
CVSS
No CVSS.
References
Configurations
No configuration.
History
29 Jul 2026, 20:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-07-29 20:17
Updated : 2026-07-30 19:27
NVD link : CVE-2026-67436
Mitre link : CVE-2026-67436
CVE.ORG link : CVE-2026-67436
JSON object : View
Products Affected
No product.
