Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade icingaweb2 | Sep 23, 2020 | Aug 19, 2020 |
| Debian | — | Upgrade icingaweb2 | Aug 25, 2020 | Aug 19, 2020 |
| Freebsd | — | Upgrade icingaweb2 | Aug 20, 2020 | Aug 19, 2020 |
| Gentoo Linux | — | Upgrade www-apps/icingaweb2. | Aug 5, 2022 | Aug 19, 2020 |
| Suse | — | Upgrade icingaweb2-vendor-lessphpUpgrade icingaweb2-vendor-htmlpurifierUpgrade icingaweb2Upgrade icingaweb2-vendor-parsedownUpgrade php-icingaUpgrade icingaweb2-commonUpgrade icingaweb2-vendor-jshrinkUpgrade icingaweb2-vendor-zf1Upgrade icingacliUpgrade icingaweb2-vendor-dompdf | Oct 17, 2020 | Aug 19, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub