Icinga
Icinga WEB 2: vulnerabilidades y CVE
Icinga WEB 2 tiene 14 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-30164 | Media (6.1) | 0.26% | — | 26 mar 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited… |
| CVE-2025-27609 | Baja (1.1) | 0.25% | — | 26 mar 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a… |
| CVE-2025-27406 | Alta (7.6) | 0.32% | — | 26 mar 2025 | Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a… |
| CVE-2025-27405 | Media (6.1) | 0.33% | — | 26 mar 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user,… |
| CVE-2025-27404 | Media (6.1) | 0.60% | — | 26 mar 2025 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user,… |
| CVE-2022-24716 | Alta (7.5) | 89% | — | 8 mar 2022 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including… |
| CVE-2022-24715 | Alta (8.8) | 15% | — | 8 mar 2022 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to… |
| CVE-2022-24714 | Media (5.3) | 1.2% | — | 8 mar 2022 | Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role… |
| CVE-2020-24368 | Alta (7.5) | 3.3% | — | 19 ago 2020 | Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is… |
| CVE-2018-18250 | Alta (7.5) | 1.00% | — | 17 dic 2018 | Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item. |
| CVE-2018-18249 | Crítica (9.8) | 1.5% | — | 17 dic 2018 | Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a… |
| CVE-2018-18248 | Media (6.1) | 0.72% | — | 17 dic 2018 | Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup query string. |
| CVE-2018-18247 | Media (5.4) | 0.58% | — | 17 dic 2018 | Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter. |
| CVE-2018-18246 | Media (6.5) | 0.46% | — | 17 dic 2018 | Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module. |