Icinga Web 2是一个应用软件。Icinga Web 2是Icinga Project开发的下一代开源监控 Web 界面、框架和命令行界面,支持 Icinga 2、Icinga Core 和任何其他兼容 IDO 数据库的监控后端。 Icinga Web 2 存在路径遍历漏洞,该漏洞源于经过身份验证的Icinga Web 2用户可以访问配置,可以在非预期目录中创建 SSH 资源文件,从而导致执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Icinga | icingaweb2 | < 2.8.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Authenticated Remote Code Execution in Icinga Web 2 <2.8.6, <2.9.6, <2.10 | https://github.com/JacobEbben/CVE-2022-24715 | POC Details |
| 2 | Icinga Web 2 - Authenticated Remote Code Execution <2.8.6, <2.9.6, <2.10 | https://github.com/cxdxnt/CVE-2022-24715 | POC Details |
| 3 | None | https://github.com/d4rkb0n3/CVE-2022-24715-go | POC Details |
No public POC found.
Login to generate AI POC| CVE-2022-24716 | 7.5 HIGH | Path traversal in Icinga Web 2 |
| CVE-2022-24714 | 5.3 MEDIUM | Disclosure of hosts and related data, linked to decommissioned services in Icinga Web 2 |
No comments yet