CVE-2025-30164
- EPSS 0.04%
- Veröffentlicht 26.03.2025 16:13:26
- Zuletzt bearbeitet 01.08.2025 15:02:24
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one...
CVE-2025-27609
- EPSS 0.05%
- Veröffentlicht 26.03.2025 16:10:19
- Zuletzt bearbeitet 01.08.2025 15:11:44
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to em...
CVE-2025-27405
- EPSS 0.05%
- Veröffentlicht 26.03.2025 15:10:10
- Zuletzt bearbeitet 01.08.2025 15:15:28
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascr...
CVE-2025-27404
- EPSS 0.05%
- Veröffentlicht 26.03.2025 14:21:05
- Zuletzt bearbeitet 01.08.2025 15:18:18
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascr...
CVE-2024-49369
- EPSS 17.66%
- Veröffentlicht 12.11.2024 17:15:08
- Zuletzt bearbeitet 13.11.2024 17:01:58
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowin...
CVE-2022-24714
- EPSS 0.33%
- Veröffentlicht 08.03.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:56
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommissio...
CVE-2022-24715
- EPSS 72.51%
- Veröffentlicht 08.03.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:56
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code....
CVE-2022-24716
- EPSS 93.18%
- Veröffentlicht 08.03.2022 20:15:07
- Zuletzt bearbeitet 21.11.2024 06:50:56
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with...
CVE-2020-24368
- EPSS 2.23%
- Veröffentlicht 19.08.2020 15:15:12
- Zuletzt bearbeitet 21.11.2024 05:14:40
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v...
CVE-2018-18246
- EPSS 0.12%
- Veröffentlicht 17.12.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:55:34
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.