Lucene search

K
cveGitHub_MCVE-2022-24714
HistoryMar 08, 2022 - 8:15 p.m.

CVE-2022-24714

2022-03-0820:15:07
CWE-863
GitHub_M
web.nvd.nist.gov
71
icinga web 2
cve-2022-24714
security vulnerability
unauthorized access
icinga 2
ido writer
role restrictions
decommission service objects

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

34.8%

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that this only applies if a role has implicitly permitted access to hosts, due to permitted access to at least one of their services. If access to a host is permitted by other means, no sensible information has been disclosed to unauthorized users. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2.

Affected configurations

Nvd
Vulners
Node
icingaicinga_web_2Range<2.8.6
OR
icingaicinga_web_2Range2.9.02.9.6
VendorProductVersionCPE
icingaicinga_web_2*cpe:2.3:a:icinga:icinga_web_2:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "icingaweb2",
    "vendor": "Icinga",
    "versions": [
      {
        "status": "affected",
        "version": "< 2.8.6"
      },
      {
        "status": "affected",
        "version": ">= 2.9.0, < 2.9.6"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI Score

6.4

Confidence

High

EPSS

0.001

Percentile

34.8%