<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Icinga</title>
  <link>https://cvedaily.com/pages/tags/icinga.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/icinga.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Icinga</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:50 +0000</lastBuildDate>
  <item>
    <title>[High] CVE-2026-42224 – ipl/web is a set of common web components for php projects. Prior to version 0.1...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-42224</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-42224</guid>
    <pubDate>Fri, 08 May 2026 23:16:35 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-42224</strong></p>
  <p>ipl/web is a set of common web components for php projects. Prior to version 0.13.1, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing. This issue has been patched in version 0.13.1.</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-42224">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2026-24893 – openITCOCKPIT is an open source monitoring tool built for different monitoring e...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24893</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24893</guid>
    <pubDate>Tue, 14 Apr 2026 21:16:24 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2026-24893</strong></p>
  <p>openITCOCKPIT is an open source monitoring tool built for different monitoring engines. openITCOCKPIT Community Edition prior to version 5.5.2 contains a command injection vulnerability that allows an authenticated user with permission to add or modify hosts to execute arbitrary OS commands on the monitoring backend. The vulnerability arises because user-controlled host attributes (specifically t…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24893">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-50942 – Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-50942</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-50942</guid>
    <pubDate>Sun, 01 Feb 2026 13:15:57 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-50942</strong></p>
  <p>Incinga Web 2.8.2 contains a client-side cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through the icinga.min.js file. Attackers can exploit the EventListener.handleEvent method to execute arbitrary scripts, potentially leading to session hijacking and non-persistent phishing attacks.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-50942">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24414 – The Icinga PowerShell Framework provides configuration and check possibilities t...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24414</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24414</guid>
    <pubDate>Thu, 29 Jan 2026 18:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24414</strong></p>
  <p>The Icinga PowerShell Framework provides configuration and check possibilities to ensure integration and monitoring of Windows environments. In versions prior to 1.13.4, 1.12.4, and 1.11.2, permissions of the Icinga for Windows `certificate` directory grant every user read access, which results in the exposure of private key of the Icinga certificate for the given host. All installations are affe…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24414">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2026-24413 – Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prio...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2026-24413</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2026-24413</guid>
    <pubDate>Thu, 29 Jan 2026 18:16:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2026-24413</strong></p>
  <p>Icinga 2 is an open source monitoring system. Starting in version 2.3.0 and prior to versions 2.13.14, 2.14.8, and 2.15.2, the Icinga 2 MSI did not set appropriate permissions for the `%ProgramData%\icinga2\var` folder on Windows. This resulted in the its contents - including the private key of the user and synced configuration - being readable by all local users. All installations on Windows are…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-276</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-24413">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61909 – Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61909</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61909</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61909</strong></p>
  <p>Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, the safe-reload script (also used during systemctl reload icinga2) and logrotate configuration shipped with Icinga 2 read the PID of the main Icinga 2 process from a PID file writable by the daemon user, but send the signal as the root user. This can allow the Icinga user to send signals to processes…</p>
  <p><strong>CVSS:</strong> 4.4 · <strong>CWE:</strong> CWE-250</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61909">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61908 – Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61908</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61908</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61908</strong></p>
  <p>Icinga 2 is an open source monitoring system. From 2.10.0 to before 2.15.1, 2.14.7, and 2.13.13, when creating an invalid reference, such as a reference to null, dereferencing results in a segmentation fault. This can be used by any API user with access to an API endpoint that allows specifying a filter expression to crash the Icinga 2 daemon. A fix is included in the following Icinga 2 versions:…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61908">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61907 – Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61907</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61907</guid>
    <pubDate>Thu, 16 Oct 2025 18:15:37 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61907</strong></p>
  <p>Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61907">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-61789 – Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-61789</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-61789</guid>
    <pubDate>Thu, 16 Oct 2025 17:15:34 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-61789</strong></p>
  <p>Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used.</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-204</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-61789">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2025-53840 – Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-53840</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-53840</guid>
    <pubDate>Wed, 16 Jul 2025 14:15:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2025-53840</strong></p>
  <p>Icinga DB Web provides a graphical interface for Icinga monitoring. Starting in version 1.2.0 and prior to version 1.2.2, users with access to Icinga Dependency Views, are allowed to see hosts and services that they weren't meant to on the dependency map. However, the name of an object will not be revealed nor does this grant access to a host's or service's detail view. Please note that this only…</p>
  <p><strong>CVSS:</strong> 2.4 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-53840">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2025-48057 – Icinga 2 is a monitoring system which checks the availability of network resourc...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-48057</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-48057</guid>
    <pubDate>Tue, 27 May 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-48057</strong></p>
  <p>Icinga 2 is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. Prior to versions 2.12.12, 2.13.12, and 2.14.6, the VerifyCertificate() function can be tricked into incorrectly treating certificates as valid. This allows an attacker to send a malicious certificate request that is then treated as a renewal…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-296</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-48057">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-30164 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-30164</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-30164</guid>
    <pubDate>Wed, 26 Mar 2025 17:15:26 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-30164</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.…</p>
  <p><strong>CVSS:</strong> 4.1 · <strong>CWE:</strong> CWE-601</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-30164">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-27609 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27609</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27609</guid>
    <pubDate>Wed, 26 Mar 2025 17:15:25 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-27609</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a…</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27609">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27406 – Icinga Reporting is the central component for reporting related functionality in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27406</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27406</guid>
    <pubDate>Wed, 26 Mar 2025 16:15:23 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27406</strong></p>
  <p>Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the user, if the template is being previewed; and act on behalf of the headless browser,…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27406">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27405 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27405</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27405</guid>
    <pubDate>Wed, 26 Mar 2025 16:15:22 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27405</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, t…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27405">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2025-27404 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-27404</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-27404</guid>
    <pubDate>Wed, 26 Mar 2025 15:16:14 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2025-27404</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, t…</p>
  <p><strong>CVSS:</strong> 7.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-27404">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2025-23203 – Icinga Director is an Icinga config deployment tool. A Security vulnerability ha...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-23203</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-23203</guid>
    <pubDate>Wed, 26 Mar 2025 14:15:32 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2025-23203</strong></p>
  <p>Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the Director is required (plus api access with regard to the api endpoints). And even though some of these Icinga Director use…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-23203">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-49369 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49369</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49369</guid>
    <pubDate>Tue, 12 Nov 2024 17:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-49369</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The TLS certificate validation in all Icinga 2 versions starting from 2.4.0 was flawed, allowing an attacker to impersonate both trusted cluster nodes as well as any API users that use TLS client certificates for authentication (ApiUser objects…</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49369">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2024-41811 – ipl/web is a set of common web components for php projects. Some of the recent d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-41811</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-41811</guid>
    <pubDate>Mon, 05 Aug 2024 21:15:38 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2024-41811</strong></p>
  <p>ipl/web is a set of common web components for php projects. Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF). All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded. Version 0.10.1 includes a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 rele…</p>
  <p><strong>CVSS:</strong> 3.9 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-41811">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2024-39915 – Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and S...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-39915</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-39915</guid>
    <pubDate>Mon, 15 Jul 2024 20:15:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2024-39915</strong></p>
  <p>Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF report generation. The Thruk web application does not properly process the url parameter when generating a PDF report. An authorized attacker with a…</p>
  <p><strong>CVSS:</strong> 9.9 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-39915">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2024-24819 – icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24819</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24819</guid>
    <pubDate>Fri, 09 Feb 2024 01:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-24819</strong></p>
  <p>icingaweb2-module-incubator is a working project of bleeding edge Icinga Web 2 libraries. In affected versions the class `gipfl\Web\Form` is the base for various concrete form implementations [1] and provides protection against cross site request forgery (CSRF) by default. This is done by automatically adding an element with a CSRF token to any form, unless explicitly disabled, but even if enable…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24819">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2024-24820 – Icinga Director is a tool designed to make Icinga 2 configuration handling easy...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-24820</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-24820</guid>
    <pubDate>Fri, 09 Feb 2024 00:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2024-24820</strong></p>
  <p>Icinga Director is a tool designed to make Icinga 2 configuration handling easy. Not any of Icinga Director's configuration forms used to manipulate the monitoring environment are protected against cross site request forgery (CSRF). It enables attackers to perform changes in the monitoring environment managed by Icinga Director without the awareness of the victim. Users of the map module in versi…</p>
  <p><strong>CVSS:</strong> 8.3 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-24820">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2023-34096 – Thruk is a multibackend monitoring webinterface which currently supports Naemon,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-34096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-34096</guid>
    <pubDate>Thu, 08 Jun 2023 19:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2023-34096</strong></p>
  <p>Thruk is a multibackend monitoring webinterface which currently supports Naemon, Icinga, Shinken and Nagios as backends. In versions 3.06 and prior, the file `panorama.pm` is vulnerable to a Path Traversal vulnerability which allows an attacker to upload a file to any folder which has write permissions on the affected system. The parameter location is not filtered, validated or sanitized and it a…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-34096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24716 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24716</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24716</guid>
    <pubDate>Tue, 08 Mar 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24716</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24716">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-24715 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24715</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24715</guid>
    <pubDate>Tue, 08 Mar 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-24715</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 conf…</p>
  <p><strong>CVSS:</strong> 8.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24715">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-24714 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-24714</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-24714</guid>
    <pubDate>Tue, 08 Mar 2022 20:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-24714</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that this only applies if a role has implicitly permi…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-24714">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-37698 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-37698</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-37698</guid>
    <pubDate>Thu, 19 Aug 2021 16:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-37698</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mention…</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-37698">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32743 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32743</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32743</guid>
    <pubDate>Thu, 15 Jul 2021 16:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32743</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-202</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32743">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2021-32739 – Icinga is a monitoring system which checks the availability of network resources...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32739</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32739</guid>
    <pubDate>Thu, 15 Jul 2021 15:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2021-32739</strong></p>
  <p>Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attributes of all config objects including `ticket_…</p>
  <p><strong>CVSS:</strong> 8.8 · <strong>CWE:</strong> CWE-267</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32739">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32747 – Icinga Web 2 is an open source monitoring web interface, framework, and command-...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32747</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32747</guid>
    <pubDate>Mon, 12 Jul 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32747</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework, and command-line interface. A vulnerability in which custom variables are exposed to unauthorized users exists between versions 2.0.0 and 2.8.2. Custom variables are user-defined keys and values on configuration objects in Icinga 2. These are commonly used to reference secrets in other configurations such as check commands to be…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-200</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32747">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2021-32746 – Icinga Web 2 is an open source monitoring web interface, framework and command-l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2021-32746</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2021-32746</guid>
    <pubDate>Mon, 12 Jul 2021 23:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2021-32746</strong></p>
  <p>Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Between versions 2.3.0 and 2.8.2, the `doc` module of Icinga Web 2 allows to view documentation directly in the UI. It must be enabled manually by an administrator and users need explicit access permission to use it. Then, by visiting a certain route, it is possible to gain access to arbitrary files rea…</p>
  <p><strong>CVSS:</strong> 5.3 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2021-32746">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2020-29663 – Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certifica...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-29663</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-29663</guid>
    <pubDate>Tue, 15 Dec 2020 23:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2020-29663</strong></p>
  <p>Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-295</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-29663">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-24368 – Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversa...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-24368</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-24368</guid>
    <pubDate>Wed, 19 Aug 2020 15:15:12 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-24368</strong></p>
  <p>Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-24368">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-18250 – Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as d...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18250</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18250</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-18250</strong></p>
  <p>Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-74</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18250">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2018-18249 – Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vector...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18249</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18249</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2018-18249</strong></p>
  <p>Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-94</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18249">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-18248 – Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter,...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18248</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18248</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-18248</strong></p>
  <p>Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18248">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-18247 – Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parame...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18247</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18247</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-18247</strong></p>
  <p>Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.</p>
  <p><strong>CVSS:</strong> 5.4 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18247">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-18246 – Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=mon...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-18246</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-18246</guid>
    <pubDate>Mon, 17 Dec 2018 15:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-18246</strong></p>
  <p>Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-18246">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6535 – An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6535</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6535</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6535</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6535">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6534 – An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6534</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6534</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6534</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause the product to crash.</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-476</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6534">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6533 – An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf fi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6533</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6533</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6533</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6533">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2018-6532 – An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafte...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6532</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6532</guid>
    <pubDate>Tue, 27 Feb 2018 19:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2018-6532</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-400</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6532">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2018-6536 – An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icing...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2018-6536</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2018-6536</guid>
    <pubDate>Fri, 02 Feb 2018 09:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2018-6536</strong></p>
  <p>An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which might allow local users to kill arbitrary processes by leveraging access to this non-root account for icinga2.pid modification before a root script executes a "kill `cat /pathname/icinga2.pid`" command, as demonstrated by icinga2.init.d.cmake.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2018-6536">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16933 – etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a f...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16933</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16933</guid>
    <pubDate>Fri, 24 Nov 2017 05:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16933</strong></p>
  <p>etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16933">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2017-16882 – Icinga Core through 1.14.0 initially executes bin/icinga as root but supports co...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2017-16882</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2017-16882</guid>
    <pubDate>Sat, 18 Nov 2017 18:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2017-16882</strong></p>
  <p>Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging access to this non-root account, a related issue to CVE-2017-14312. This also affects bin/icingastats, bin/ido2db, and bin…</p>
  <p><strong>CVSS:</strong> 7.8 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2017-16882">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2015-8010 – Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export l...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2015-8010</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2015-8010</guid>
    <pubDate>Mon, 27 Mar 2017 17:59:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2015-8010</strong></p>
  <p>Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inject arbitrary web script or HTML via the query string to cgi-bin/status.cgi.</p>
  <p><strong>CVSS:</strong> 6.1 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2015-8010">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2014-8994 – The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local use...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-8994</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-8994</guid>
    <pubDate>Fri, 28 Nov 2014 15:59:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2014-8994</strong></p>
  <p>The check_diskio plugin 3.2.6 and earlier for Nagios and Icinga allows local users to write to arbitrary files via a symlink attack on a temporary file with a predictable name (tmp/check_diskio_status-*-*).</p>
  <p><strong>CVSS:</strong> 3.6 · <strong>CWE:</strong> CWE-18</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-8994">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-2386 – Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-2386</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-2386</guid>
    <pubDate>Tue, 25 Mar 2014 16:55:28 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-2386</strong></p>
  <p>Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (1) display_nav_table, (2) print_export_link, (3) page_num_selector, or (4) page_limit_selector function in cgi/cgiutils.c or (5) status_page_num_selector function in cgi/status.c, which triggers a stack-based buffer overflow.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-189</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-2386">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2014-1878 – Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios C...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2014-1878</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2014-1878</guid>
    <pubDate>Fri, 28 Feb 2014 15:13:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2014-1878</strong></p>
  <p>Stack-based buffer overflow in the cmd_submitf function in cgi/cmd.c in Nagios Core, possibly 4.0.3rc1 and earlier, and Icinga before 1.8.6, 1.9 before 1.9.5, and 1.10 before 1.10.3 allows remote attackers to cause a denial of service (segmentation fault) via a long message to cmd.cgi.</p>
  <p><strong>CVSS:</strong> 5.0 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2014-1878">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7108 – Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7108</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7108</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:04 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7108</strong></p>
  <p>Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) exti…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-20</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7108">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7107 – Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7107</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7107</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7107</strong></p>
  <p>Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.</p>
  <p><strong>CVSS:</strong> 6.8 · <strong>CWE:</strong> CWE-352</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7107">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2013-7106 – Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2013-7106</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2013-7106</guid>
    <pubDate>Wed, 15 Jan 2014 16:08:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2013-7106</strong></p>
  <p>Multiple stack-based buffer overflows in Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to cause a denial of service (crash) and possibly execute arbitrary code via a long string to the (1) display_nav_table, (2) page_limit_selector, (3) print_export_link, or (4) page_num_selector function in cgi/cgiutils.c; (5) status_page_num_selector function in…</p>
  <p><strong>CVSS:</strong> 6.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2013-7106">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-6096 – Multiple stack-based buffer overflows in the get_history function in history.cgi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-6096</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-6096</guid>
    <pubDate>Tue, 22 Jan 2013 23:55:03 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-6096</strong></p>
  <p>Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2, 1.7.x before 1.7.4, and 1.8.x before 1.8.4, might allow remote attackers to execute arbitrary code via a long (1) host_name variable (host parameter) or (2) svc_description variable.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-119</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-6096">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2012-3441 – The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in I...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2012-3441</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2012-3441</guid>
    <pubDate>Sat, 25 Aug 2012 10:29:51 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2012-3441</strong></p>
  <p>The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-264</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2012-3441">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Low] CVE-2011-2477 – Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2477</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2477</guid>
    <pubDate>Tue, 14 Jun 2011 17:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk low">Low</span> CVE-2011-2477</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in Icinga before 1.4.1, when escape_html_tags is disabled, allow remote attackers to inject arbitrary web script or HTML via a JavaScript expression, as demonstrated by the onload attribute of a BODY element located after a check-host-alive! sequence, a different vulnerability than CVE-2011-2179.</p>
  <p><strong>CVSS:</strong> 2.6 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2477">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2011-2179 – Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2011-2179</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2011-2179</guid>
    <pubDate>Tue, 14 Jun 2011 17:55:06 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2011-2179</strong></p>
  <p>Multiple cross-site scripting (XSS) vulnerabilities in config.c in config.cgi in (1) Nagios 3.2.3 and (2) Icinga before 1.4.1 allow remote attackers to inject arbitrary web script or HTML via the expand parameter, as demonstrated by an (a) command action or a (b) hosts action.</p>
  <p><strong>CVSS:</strong> 4.3 · <strong>CWE:</strong> CWE-79</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2011-2179">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
