Icinga · Icinga Web 2 · CVE-2020-24368
**Name of the Vulnerable Software and Affected Versions**
Icinga Web2 versions 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 are not accurate representations, as the issue is fixed in these versions.
Icinga Web2 versions prior to 2.6.4, prior to 2.7.4, and prior to 2.8.2
**Description**
The issue allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2 due to incorrect restriction of the directory path name with limited access. This enables a remote attacker to gain access to arbitrary files readable by the Icinga Web 2 process.
**Recommendations**
For versions prior to 2.6.4, update to version 2.6.4 or later.
For versions prior to 2.7.4, update to version 2.7.4 or later.
For versions prior to 2.8.2, update to version 2.8.2 or later.