Aller au contenu

Fiche vulnérabilité

CVE-2022-24716 : faille élevée icinga icinga web 2 (CVSS 7.5)

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

En bref

Sévérité
Élevée (CVSS 7.5)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitation active
Non signalée par la CISA
Publication
8 mars 2022
Dernière mise à jour
17 juin 2026

Produits concernés

  • icinga icinga web 2

Références

Rechercher une autre vulnérabilité dans la base CVE