Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.
CVSS Details
- CVSS 3.1 Base Score: 8.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade icingaweb2 | Jul 30, 2024 | Mar 8, 2022 |
| Gentoo Linux | — | Upgrade www-apps/icingaweb2. | Aug 5, 2022 | Mar 8, 2022 |
| Suse | — | Upgrade icingaweb2-vendor-htmlpurifierUpgrade icingaweb2Upgrade icingaweb2-vendor-lessphpUpgrade icingaweb2-vendor-parsedownUpgrade icingaweb2-vendor-zf1Upgrade php-icingaUpgrade icingacliUpgrade icingaweb2-vendor-dompdfUpgrade icingaweb2-commonUpgrade icingaweb2-vendor-jshrink | Mar 22, 2022 | Mar 8, 2022 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Mar 8, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub