CVE-2022-24716
Summary
| CVE | CVE-2022-24716 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-03-08 20:15:00 UTC |
| Updated | 2023-04-10 20:15:00 UTC |
| Description | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Icinga |
Icinga Web 2 |
All |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| Icinga Web 2.10 Arbitrary File Disclosure ≈ Packet Storm |
MISC |
packetstormsecurity.com |
|
| Icinga Web 2: Multiple Vulnerabilities (GLSA 202208-05) — Gentoo security |
GENTOO |
security.gentoo.org |
|
| Merge pull request from GHSA-5p3f-rh28-8frw · Icinga/icingaweb2@9931ed7 · GitHub |
MISC |
github.com |
|
| Path traversal in static library file requests for unauthenticated users · Advisory · Icinga/icingaweb2 · GitHub |
CONFIRM |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 183632 Debian Security Update for icingaweb2 (CVE-2022-24716)
- 710576 Gentoo Linux Icinga Web 2 Multiple Vulnerabilities (GLSA 202208-05)