Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Lars Vogdt

Researcher fromSUSE
#37320of 53,632
7.5Total CVSS
Vulnerabilities · 1
PT-2012-4714
7.5
2012-08-25
Icinga · Icinga · CVE-2012-3441
**Name of the Vulnerable Software and Affected Versions** Icinga version 1.7.1 **Description** The issue in Icinga allows the icinga user to access all databases due to the database creation script granting excessive access. This could potentially be exploited via unspecified vectors, allowing icinga users to access other databases. **Recommendations** For Icinga version 1.7.1, consider restricting the access rights of the icinga user to prevent unauthorized access to other databases. As a temporary workaround, review and modify the database creation script (module/idoutils/db/scripts/create mysqldb.sh) to ensure it grants the least privileges necessary for the icinga user.