PT-2021-6530 · Icinga+1 · Icinga Web 2+1
Nilmerg
·
Published
2021-07-12
·
Updated
2021-07-15
·
CVE-2021-32746
CVSS v2.0
6.3
Medium
| Vector | AV:N/AC:M/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Icinga Web 2 versions 2.3.0 through 2.8.2
Description
The issue in Icinga Web 2's
doc module allows an attacker to gain access to arbitrary files readable by the web-server user by visiting a certain route. The doc module must be manually enabled by an administrator, and users need explicit access permission to use it. This issue can be exploited remotely, allowing an attacker to access confidential data.Recommendations
For versions 2.3.0 through 2.8.2, update to version 2.9.0, 2.8.3, or 2.7.5 to resolve the issue.
As a temporary workaround, consider disabling the
doc module or revoking permission to use it from all users.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Icinga Web 2