PT-2025-12974 · Icinga+2 · Icinga Web 2+2

Moezbouzayani9

·

Publicado

2025-03-26

·

Atualizado

2025-08-21

·

CVE-2025-27609

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Icinga Web 2 versions prior to 2.11.5 Icinga Web 2 versions prior to 2.12.13
Description A vulnerability in Icinga Web 2 allows an attacker to craft a request that embeds arbitrary Javascript into the interface, enabling them to act on behalf of a user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. Modern browsers with a working CORS implementation sufficiently guard against the vulnerability.
Recommendations For versions prior to 2.11.5, update to version 2.11.5 or later. For versions prior to 2.12.13, update to version 2.12.3 or later. As a temporary workaround for version 2.12.2, enable a content security policy in the application settings.

Exploit

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2025-10627
CVE-2025-27609
GHSA-5CJW-FWJC-8J38
OPENSUSE-SU-2025:14931-1

Produtos afetados

Alt Linux
Debian
Icinga Web 2