CVE-2022-24716
08.03.2022, 20:15
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.
Vendor | Product | Version |
---|---|---|
icinga | icinga_web_2 | 2.9.0 ≤ 𝑥 < 2.9.6 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
References