Lucene search

K
osvGoogleOSV:CVE-2022-24715
HistoryMar 08, 2022 - 8:15 p.m.

CVE-2022-24715

2022-03-0820:15:07
Google
osv.dev
11
icinga web 2
monitoring web interface
ssh resource files
arbitrary code
security issue

AI Score

6.9

Confidence

Low

EPSS

0.004

Percentile

74.2%

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.