PT-2012-4714 · Icinga · Icinga

Lars Vogdt

·

Published

2012-08-25

·

Updated

2017-08-29

·

CVE-2012-3441

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Icinga version 1.7.1
Description The issue in Icinga allows the icinga user to access all databases due to the database creation script granting excessive access. This could potentially be exploited via unspecified vectors, allowing icinga users to access other databases.
Recommendations For Icinga version 1.7.1, consider restricting the access rights of the icinga user to prevent unauthorized access to other databases. As a temporary workaround, review and modify the database creation script (module/idoutils/db/scripts/create mysqldb.sh) to ensure it grants the least privileges necessary for the icinga user.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-3441

Affected Products

Icinga