Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2022-24716

Опубликовано: 08 мар. 2022
Источник: debian

Описание

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
icingaweb2fixed2.9.6-1package
icingaweb2not-affectedbullseyepackage
icingaweb2not-affectedbusterpackage
icingaweb2not-affectedstretchpackage

Примечания

  • https://github.com/Icinga/icingaweb2/security/advisories/GHSA-5p3f-rh28-8frw

  • https://github.com/Icinga/icingaweb2/commit/9931ed799650f5b8d5e1dc58ea3415a4cdc5773d

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

CVSS3: 7.5
nvd
почти 4 года назад

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

CVSS3: 7.5
fstec
почти 4 года назад

Уязвимость PHP фреймворка Icinga Web 2, позволяющая нарушителю выполнить произвольный код