Skip to content
Noroxi

icinga records

49 published records for vendor icinga.

All records

49 records
  • Path traversal in Icinga Web 2

    HighCVSS 7.5WeaponizedEPSS 89%

    icinga · icinga web 2Mar 8, 2022

  • Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,

    HighCVSS 7.5WeaponizedEPSS 66%

    nagios · nagiosJan 22, 2013

  • Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow

    MediumCVSS 5.5Proof of conceptEPSS 60%

    nagios · nagiosJan 15, 2014

  • Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    icinga · icingaNov 12, 2024

  • Arbitrary code execution for authenticated users in Icinga Web 2

    HighCVSS 8.8Proof of conceptEPSS 15%

    icinga · icinga web 2Mar 8, 2022

  • Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inf

    CriticalCVSS 9.8No exploitEPSS 1%

    icinga · icinga web 2Dec 17, 2018

  • Icinga 2 certificate renewal might incorrectly renew an invalid certificate

    CriticalCVSS 9.3No exploitEPSS 0%

    icinga · icingaMay 27, 2025

  • Passwords used to access external services inadvertently exposed through API

    HighCVSS 8.8No exploitEPSS 2%

    icinga · icingaJul 15, 2021

  • Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring

    CriticalCVSS 9.1No exploitEPSS 2%

    icinga · icingaDec 15, 2020

  • Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities

    HighCVSS 8.8No exploitEPSS 1%

    icinga · icingaJul 15, 2021

  • icingaweb2-module-jira template and field configuration are susceptible to CSRF

    HighCVSS 8.8No exploitEPSS 0%

    icinga · icinga web jira integrationJul 5, 2023

  • icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRF

    HighCVSS 8.8No exploitEPSS 0%

    icinga · icingaweb2-module-incubatorFeb 8, 2024

  • Icinga Director configuration is susceptible to Cross-Site Request Forgery

    HighCVSS 8.3No exploitEPSS 0%

    icinga · icingaFeb 8, 2024

  • CVE-2018-6535
    32Monitor

    An issue was discovered in Icinga 2.x through 2.8.1.

    HighCVSS 8.1No exploitEPSS 1%

    icinga · icingaFeb 27, 2018

  • Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary

    HighCVSS 7.5No exploitEPSS 3%

    icinga · icinga web 2Aug 19, 2020

  • CVE-2012-3441
    31Monitor

    The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga use

    HighCVSS 7.5No exploitEPSS 2%

    icinga · icingaAug 25, 2012

  • An issue was discovered in Icinga2 before v2.12.0-rc1.

    HighCVSS 7.8No exploitEPSS 1%

    icinga · icingaJun 12, 2020

  • CVE-2018-6533
    31Monitor

    An issue was discovered in Icinga 2.x through 2.8.1.

    HighCVSS 7.8No exploitEPSS 0%

    icinga · icingaFeb 27, 2018

  • Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-roo

    HighCVSS 7.8No exploitEPSS 0%

    icinga · icingaNov 18, 2017

  • Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer

    HighCVSS 7.5No exploitEPSS 1%

    icinga · icingaAug 19, 2021

  • CVE-2018-6532
    30Monitor

    An issue was discovered in Icinga 2.x through 2.8.1.

    HighCVSS 7.5No exploitEPSS 1%

    icinga · icingaFeb 27, 2018

  • Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navig

    HighCVSS 7.5No exploitEPSS 1%

    icinga · icinga web 2Dec 17, 2018

  • Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference

    HighCVSS 7.1No exploitEPSS 1%

    icinga · icingaOct 16, 2025

  • Icinga 2 API users could access restricted values in filter expressions

    HighCVSS 7.1No exploitEPSS 0%

    icinga · icingaOct 16, 2025

  • etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local use

    HighCVSS 7.0No exploitEPSS 0%

    icinga · icingaNov 24, 2017