Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-30164


Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.


Published

2025-03-26T17:15:26.560

Last Modified

2025-08-01T15:02:24.357

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.1 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-601

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application icinga icinga_web_2 < 2.11.5 Yes
Application icinga icinga_web_2 < 2.12.3 Yes

References