PT-2025-29826 · Unknown · Icinga Db Web

Nilmerg

·

Published

2025-07-16

·

Updated

2025-12-11

·

CVE-2025-53840

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icinga DB Web versions 1.2.0 through 1.2.1
Description Icinga DB Web, a graphical interface for Icinga monitoring, allows users with access to Icinga Dependency Views to view hosts and services they are not authorized to access on the dependency map. The name of the object is not revealed, and access to detail views is not granted. This issue affects the filter/hosts and filter/services restrictions.
Recommendations Downgrade to version 1.1.3. Update to version 1.2.2.

Exploit

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-53840
GHSA-Q2W7-MRX8-5473

Affected Products

Icinga Db Web