PT-2022-16823 · Icinga+1 · Icinga 2+2

Nilmerg

·

Published

2022-03-08

·

Updated

2022-11-09

·

CVE-2022-24714

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icinga Web 2 versions prior to 2.8.6 Icinga Web 2 versions prior to 2.9.6 Icinga Web 2 versions prior to 2.10
Description Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that this only applies if a role has implicitly permitted access to hosts, due to permitted access to at least one of their services. If access to a host is permitted by other means, no sensible information has been disclosed to unauthorized users.
Recommendations For Icinga Web 2 versions prior to 2.8.6, update to version 2.8.6 or later. For Icinga Web 2 versions prior to 2.9.6, update to version 2.9.6 or later. For Icinga Web 2 versions prior to 2.10, update to version 2.10 or later.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-24714
GHSA-QCMG-VR56-X9WF
OPENSUSE-SU-2022:0087-1
OPENSUSE-SU-2022:0097-1

Affected Products

Debian
Icinga 2
Icinga Web 2