Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-53840

Опубликовано: 16 июл. 2025
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 2.4

Описание

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be revealed nor does this grant access to a host's or service's detail view. Please note that this only affects the restrictions filter/hosts and filter/services. filter/objects is not affected by this and restricts objects as it is supposed to. Version 1.2.2 applies these restrictions properly. As a workaround, one may downgrade to version 1.1.3.

РелизСтатусПримечание
devel

not-affected

code not present
esm-apps/noble

not-affected

code not present
jammy

DNE

noble

not-affected

code not present
plucky

not-affected

code not present
upstream

not-affected

debian: Only affects 1.2.0 and later

Показывать по

EPSS

Процентиль: 7%
0.0003
Низкий

2.4 Low

CVSS3

Связанные уязвимости

CVSS3: 2.4
nvd
около 1 месяца назад

Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be revealed nor does this grant access to a host's or service's detail view. Please note that this only affects the restrictions `filter/hosts` and `filter/services`. `filter/objects` is not affected by this and restricts objects as it is supposed to. Version 1.2.2 applies these restrictions properly. As a workaround, one may downgrade to version 1.1.3.

CVSS3: 2.4
debian
около 1 месяца назад

Icinga DB Web provides a graphical interface for Icinga monitoring. St ...

EPSS

Процентиль: 7%
0.0003
Низкий

2.4 Low

CVSS3

Уязвимость CVE-2025-53840