PT-2022-16823 · Icinga+1 · Icinga 2+2
Nilmerg
·
Published
2022-03-08
·
Updated
2022-11-09
·
CVE-2022-24714
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Icinga Web 2 versions prior to 2.8.6
Icinga Web 2 versions prior to 2.9.6
Icinga Web 2 versions prior to 2.10
Description
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that this only applies if a role has implicitly permitted access to hosts, due to permitted access to at least one of their services. If access to a host is permitted by other means, no sensible information has been disclosed to unauthorized users.
Recommendations
For Icinga Web 2 versions prior to 2.8.6, update to version 2.8.6 or later.
For Icinga Web 2 versions prior to 2.9.6, update to version 2.9.6 or later.
For Icinga Web 2 versions prior to 2.10, update to version 2.10 or later.
Exploit
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Debian
Icinga 2
Icinga Web 2