CVE-2025-61909
- EPSS 0.02%
- Veröffentlicht 16.10.2025 17:20:14
- Zuletzt bearbeitet 29.10.2025 20:03:42
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 pr...
CVE-2025-61908
- EPSS 0.06%
- Veröffentlicht 16.10.2025 17:16:58
- Zuletzt bearbeitet 26.11.2025 14:57:15
Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with acc...
CVE-2025-61907
- EPSS 0.03%
- Veröffentlicht 16.10.2025 17:11:59
- Zuletzt bearbeitet 26.11.2025 15:04:24
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows a...
CVE-2025-48057
- EPSS 0.04%
- Veröffentlicht 27.05.2025 16:32:29
- Zuletzt bearbeitet 05.12.2025 00:12:22
Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be trick...
CVE-2024-49369
- EPSS 14.77%
- Veröffentlicht 12.11.2024 17:15:08
- Zuletzt bearbeitet 26.11.2025 13:01:15
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowin...
CVE-2024-24820
- EPSS 0.07%
- Veröffentlicht 09.02.2024 00:15:08
- Zuletzt bearbeitet 21.11.2024 08:59:47
Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attack...
CVE-2021-37698
- EPSS 0.2%
- Veröffentlicht 19.08.2021 16:15:12
- Zuletzt bearbeitet 03.11.2025 22:15:49
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2...
CVE-2021-32743
- EPSS 1.03%
- Veröffentlicht 15.07.2021 16:15:09
- Zuletzt bearbeitet 03.11.2025 22:15:48
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga...
CVE-2021-32739
- EPSS 0.78%
- Veröffentlicht 15.07.2021 15:15:08
- Zuletzt bearbeitet 03.11.2025 22:15:48
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege esca...
CVE-2021-32747
- EPSS 0.51%
- Veröffentlicht 12.07.2021 23:15:07
- Zuletzt bearbeitet 21.11.2024 06:07:39
Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined key...