Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-24715
HistoryMar 08, 2022 - 12:00 a.m.

CVE-2022-24715

2022-03-0800:00:00
ubuntu.com
ubuntu.com
54
icinga web 2
authenticated users
ssh resource files
arbitrary code execution
versions 2.8.6
2.9.6
2.10
configuration access limit
unix

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.2%

Icinga Web 2 is an open source monitoring web interface, framework and
command-line interface. Authenticated users, with access to the
configuration, can create SSH resource files in unintended directories,
leading to the execution of arbitrary code. This issue has been resolved in
versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade
should limit access to the Icinga Web 2 configuration.

CVSS2

6

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.004

Percentile

74.2%