PT-2018-14378 · Icinga+1 · Icinga Web 2+1

Publicado

2018-12-17

·

Atualizado

2020-01-16

·

CVE-2018-18246

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Icinga Web 2 versions prior to 2.6.2
Description The issue allows for CSRF attacks, potentially enabling an attacker to disable the monitoring module or enable the setup module without proper authorization. This can be achieved through specific API endpoints, such as "/icingaweb2/config/moduledisable?name=monitoring" to disable the monitoring module, or "/icingaweb2/config/moduleenable?name=setup" to enable the setup module.
Recommendations For versions prior to 2.6.2, update to version 2.6.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the "/icingaweb2/config/moduledisable" and "/icingaweb2/config/moduleenable" endpoints to minimize the risk of exploitation.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-18246
OPENSUSE-SU-2020:0067-1
OPENSUSE-SU-2020_0067-1
OPENSUSE-SU-2024:10857-1

Produtos afetados

Icinga Web 2
Suse