PT-2020-6144 · Icinga+1 · Icinga Web 2+1

Nilmergo

·

Published

2020-08-19

·

Updated

2022-12-13

·

CVE-2020-24368

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icinga Web2 versions 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 are not accurate representations, as the issue is fixed in these versions. Icinga Web2 versions prior to 2.6.4, prior to 2.7.4, and prior to 2.8.2
Description The issue allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2 due to incorrect restriction of the directory path name with limited access. This enables a remote attacker to gain access to arbitrary files readable by the Icinga Web 2 process.
Recommendations For versions prior to 2.6.4, update to version 2.6.4 or later. For versions prior to 2.7.4, update to version 2.7.4 or later. For versions prior to 2.8.2, update to version 2.8.2 or later.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03172
CVE-2020-24368
DLA-2343-1
DSA-4747-1
OPENSUSE-SU-2020:1674-1
OPENSUSE-SU-2020_1674-1
OPENSUSE-SU-2024:10857-1

Affected Products

Icinga Web 2
Suse