Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-24715


Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.


Published

2022-03-08T20:15:07.777

Last Modified

2024-11-21T06:50:56.267

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.5 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Secondary
    CWE-22

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icinga icinga_web_2 < 2.8.6 Yes
Application icinga icinga_web_2 < 2.9.6 Yes

References