Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-61789

Опубликовано: 16 окт. 2025
Источник: nvd
CVSS3: 5.3
CVSS3: 6.5
EPSS Низкий

Описание

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:icinga:icinga_db_web:*:*:*:*:*:*:*:*
Версия до 1.1.4 (исключая)
cpe:2.3:a:icinga:icinga_db_web:*:*:*:*:*:*:*:*
Версия от 1.2.0 (включая) до 1.2.3 (исключая)

EPSS

Процентиль: 15%
0.00048
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-204

Связанные уязвимости

CVSS3: 5.3
ubuntu
4 месяца назад

Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used.

CVSS3: 5.3
debian
4 месяца назад

Icinga DB Web provides a graphical interface for Icinga monitoring. Be ...

EPSS

Процентиль: 15%
0.00048
Низкий

5.3 Medium

CVSS3

6.5 Medium

CVSS3

Дефекты

CWE-204