Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-24715

Опубликовано: 08 мар. 2022
Источник: ubuntu
Приоритет: medium
EPSS Высокий
CVSS2: 6
CVSS3: 8.5

Описание

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

2.11.1-1
esm-apps/bionic

needed

esm-apps/focal

needed

esm-apps/jammy

needed

esm-apps/noble

not-affected

2.11.1-1
esm-apps/xenial

needed

focal

ignored

end of standard support, was needed
impish

ignored

end of life
jammy

needed

Показывать по

EPSS

Процентиль: 99%
0.72512
Высокий

6 Medium

CVSS2

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
nvd
почти 4 года назад

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.

CVSS3: 8.5
debian
почти 4 года назад

Icinga Web 2 is an open source monitoring web interface, framework and ...

suse-cvrf
почти 4 года назад

Security update for icingaweb2

EPSS

Процентиль: 99%
0.72512
Высокий

6 Medium

CVSS2

8.5 High

CVSS3