<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Icinga (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/icinga.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/icinga-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Icinga (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-42224 – ipl/web is a set of common web components for php projects. Prior to version 0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42224</guid>
    <pubDate>Fri, 08 May 2026 23:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42224</strong></p>
  <p>ipl/web is a set of common web components for php projects. Prior to version 0.13.1, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in version 0.13.1.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24893 – openITCOCKPIT is an open source monitoring tool built for different monitoring e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24893</guid>
    <pubDate>Tue, 14 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24893</strong></p>
  <p>openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. The vulnerability arises because user-controlled host attributes (specifically t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48057 – Icinga 2 is a monitoring system which checks the availability of network resourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48057</guid>
    <pubDate>Tue, 27 May 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48057</strong></p>
  <p>Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-296</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27406 – Icinga Reporting is the central component for reporting related functionality in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27406</guid>
    <pubDate>Wed, 26 Mar 2025 16:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27406</strong></p>
  <p>Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the user, if the template is being previewed; and act on behalf of the headless browser,…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27405 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27405</guid>
    <pubDate>Wed, 26 Mar 2025 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27405</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, t…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27404 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27404</guid>
    <pubDate>Wed, 26 Mar 2025 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27404</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, t…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-49369 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49369</guid>
    <pubDate>Tue, 12 Nov 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-49369</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39915 – Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39915</guid>
    <pubDate>Mon, 15 Jul 2024 20:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39915</strong></p>
  <p>Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF report generation. The Thruk web application does not properly process the url parameter when generating a PDF report. An authorized attacker with a…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24820 – Icinga Director is a tool designed to make Icinga 2 configuration handling easy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24820</guid>
    <pubDate>Fri, 09 Feb 2024 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24820</strong></p>
  <p>Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the monitoring environment managed by Icinga Director without the awareness of the victim. Users of the map module in versi…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24716 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24716</guid>
    <pubDate>Tue, 08 Mar 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24716</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24715 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24715</guid>
    <pubDate>Tue, 08 Mar 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24715</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 conf…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37698 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37698</guid>
    <pubDate>Thu, 19 Aug 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37698</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mention…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32743 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32743</guid>
    <pubDate>Thu, 15 Jul 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32743</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-202</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32739 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32739</guid>
    <pubDate>Thu, 15 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32739</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attributes of all config objects including `ticket_…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-29663 – Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certifica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29663</guid>
    <pubDate>Tue, 15 Dec 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-29663</strong></p>
  <p>Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24368 – Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24368</guid>
    <pubDate>Wed, 19 Aug 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24368</strong></p>
  <p>Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18250 – Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18250</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18250</strong></p>
  <p>Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-18249 – Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vector...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18249</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-18249</strong></p>
  <p>Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6535 – An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6535</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6535</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6533 – An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6533</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6533</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6532 – An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6532</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6532</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16933 – etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16933</guid>
    <pubDate>Fri, 24 Nov 2017 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16933</strong></p>
  <p>etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16882 – Icinga Core through 1.14.0 initially executes bin/icinga as root but supports co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16882</guid>
    <pubDate>Sat, 18 Nov 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16882</strong></p>
  <p>Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-6096 – Multiple stack-based buffer overflows in the get_history function in history.cgi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6096</guid>
    <pubDate>Tue, 22 Jan 2013 23:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-6096</strong></p>
  <p>Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-3441 – The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3441</guid>
    <pubDate>Sat, 25 Aug 2012 10:29:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-3441</strong></p>
  <p>The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3441">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
