PT-2021-6530 · Icinga+1 · Icinga Web 2+1

Nilmerg

·

Published

2021-07-12

·

Updated

2021-07-15

·

CVE-2021-32746

CVSS v2.0

6.3

Medium

VectorAV:N/AC:M/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icinga Web 2 versions 2.3.0 through 2.8.2
Description The issue in Icinga Web 2's doc module allows an attacker to gain access to arbitrary files readable by the web-server user by visiting a certain route. The doc module must be manually enabled by an administrator, and users need explicit access permission to use it. This issue can be exploited remotely, allowing an attacker to access confidential data.
Recommendations For versions 2.3.0 through 2.8.2, update to version 2.9.0, 2.8.3, or 2.7.5 to resolve the issue. As a temporary workaround, consider disabling the doc module or revoking permission to use it from all users.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01790
CVE-2021-32746
GHSA-CMGC-H4CX-3V43

Affected Products

Debian
Icinga Web 2