Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2022-24714— Disclosure of hosts and related data, linked to decommissioned services in Icinga Web 2

Quick assessment

Affected
Icinga icingaweb2
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Icinga Web 2是一个应用软件。Icinga Web 2是Icinga Project开发的下一代开源监控 Web 界面、框架和命令行界面,支持 Icinga 2、Icinga Core 和任何其他兼容 IDO 数据库的监控后端。 Icinga Web 2 存在安全漏洞,该漏洞源于启用IDO写入器的Icinga Web 2 的安装将受到影响。

CVSS 5.3 · Medium EPSS 1.23% · P66

Possible ATT&CK Techniques 1 AI

T1530 · Data from Cloud Storage
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-24714

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Disclosure of hosts and related data, linked to decommissioned services in Icinga Web 2
Source: CVE Program / CVE List V5
Vulnerability Description
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that this only applies if a role has implicitly permitted access to hosts, due to permitted access to at least one of their services. If access to a host is permitted by other means, no sensible information has been disclosed to unauthorized users. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制不正确
Source: CVE Program / CVE List V5
Vulnerability Title
Icinga Web 2 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Icinga Web 2是一个应用软件。Icinga Web 2是Icinga Project开发的下一代开源监控 Web 界面、框架和命令行界面,支持 Icinga 2、Icinga Core 和任何其他兼容 IDO 数据库的监控后端。 Icinga Web 2 存在安全漏洞,该漏洞源于启用IDO写入器的Icinga Web 2 的安装将受到影响。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Icinga icingaweb2 < 2.8.6 -

II. Public POCs for CVE-2022-24714

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-24714

登录查看更多情报信息。

Patches & Fixes for CVE-2022-24714 (1)

Vendor Advisories for CVE-2022-24714 (2)

Same Patch Batch · Icinga · 2022-03-08 · 3 CVEs total

CVE-2022-24715 8.5 HIGH Arbitrary code execution for authenticated users in Icinga Web 2
CVE-2022-24716 7.5 HIGH Path traversal in Icinga Web 2

IV. Related Vulnerabilities

V. Comments for CVE-2022-24714

No comments yet


Leave a comment