Записи Icinga
49 опубликованных записей вендора icinga.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 2 · 4,1 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 85,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-295 Improper Certificate Validation3
- CWE-732 Incorrect Permission Assignment for Critical Resource3
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
49 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
57В плане | CVE-2022-24716Готовый эксплойт | Path traversal in Icinga Web 2icinga · icinga web 2 · CWE-22 | Высокая7,5 | — | 89,4 % | 8 мар. 2022 г. |
50В плане | CVE-2012-6096Готовый эксплойт | Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,nagios · nagios · CWE-119 | Высокая7,5 | — | 66,5 % | 22 янв. 2013 г. |
40В плане | CVE-2013-7108Proof of concept | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allownagios · nagios · CWE-20 | Средняя5,5 | — | 59,5 % | 15 янв. 2014 г. |
40В плане | CVE-2024-49369Proof of concept | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connectionsicinga · icinga · CWE-295 | Критическая9,8 | — | 2,9 % | 12 нояб. 2024 г. |
39Наблюдать | CVE-2022-24715Proof of concept | Arbitrary code execution for authenticated users in Icinga Web 2icinga · icinga web 2 · CWE-22 | Высокая8,8 | — | 14,7 % | 8 мар. 2022 г. |
39Наблюдать | CVE-2018-18249Эксплойта нет | Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inficinga · icinga web 2 · CWE-94 | Критическая9,8 | — | 1,5 % | 17 дек. 2018 г. |
37Наблюдать | CVE-2025-48057Эксплойта нет | Icinga 2 certificate renewal might incorrectly renew an invalid certificateicinga · icinga · CWE-296 | Критическая9,3 | — | 0,4 % | 27 мая 2025 г. |
36Наблюдать | CVE-2021-32743Эксплойта нет | Passwords used to access external services inadvertently exposed through APIicinga · icinga · CWE-202 | Высокая8,8 | — | 1,8 % | 15 июл. 2021 г. |
36Наблюдать | CVE-2020-29663Эксплойта нет | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring icinga · icinga · CWE-295 | Критическая9,1 | — | 1,6 % | 15 дек. 2020 г. |
35Наблюдать | CVE-2021-32739Эксплойта нет | Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identitiesicinga · icinga · CWE-267 | Высокая8,8 | — | 1,1 % | 15 июл. 2021 г. |
35Наблюдать | CVE-2023-30607Эксплойта нет | icingaweb2-module-jira template and field configuration are susceptible to CSRFicinga · icinga web jira integration · CWE-352 | Высокая8,8 | — | 0,3 % | 5 июл. 2023 г. |
35Наблюдать | CVE-2024-24819Эксплойта нет | icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRFicinga · icingaweb2-module-incubator · CWE-352 | Высокая8,8 | — | 0,3 % | 8 февр. 2024 г. |
33Наблюдать | CVE-2024-24820Эксплойта нет | Icinga Director configuration is susceptible to Cross-Site Request Forgeryicinga · icinga · CWE-352 | Высокая8,3 | — | 0,4 % | 8 февр. 2024 г. |
32Наблюдать | CVE-2018-6535Эксплойта нет | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga | Высокая8,1 | — | 1,3 % | 27 февр. 2018 г. |
31Наблюдать | CVE-2020-24368Эксплойта нет | Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitraryicinga · icinga web 2 · CWE-22 | Высокая7,5 | — | 3,3 % | 19 авг. 2020 г. |
31Наблюдать | CVE-2012-3441Эксплойта нет | The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga useicinga · icinga · CWE-264 | Высокая7,5 | — | 2,4 % | 25 авг. 2012 г. |
31Наблюдать | CVE-2020-14004Эксплойта нет | An issue was discovered in Icinga2 before v2.12.0-rc1.icinga · icinga · CWE-59 | Высокая7,8 | — | 0,7 % | 12 июн. 2020 г. |
31Наблюдать | CVE-2018-6533Эксплойта нет | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga | Высокая7,8 | — | 0,4 % | 27 февр. 2018 г. |
31Наблюдать | CVE-2017-16882Эксплойта нет | Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-rooicinga · icinga · CWE-732 | Высокая7,8 | — | 0,3 % | 18 нояб. 2017 г. |
30Наблюдать | CVE-2021-37698Эксплойта нет | Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writericinga · icinga · CWE-295 | Высокая7,5 | — | 1,4 % | 19 авг. 2021 г. |
30Наблюдать | CVE-2018-6532Эксплойта нет | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga · CWE-400 | Высокая7,5 | — | 1,4 % | 27 февр. 2018 г. |
30Наблюдать | CVE-2018-18250Эксплойта нет | Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigicinga · icinga web 2 · CWE-74 | Высокая7,5 | — | 1,0 % | 17 дек. 2018 г. |
28Наблюдать | CVE-2025-61908Эксплойта нет | Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Referenceicinga · icinga · CWE-476 | Высокая7,1 | — | 0,5 % | 16 окт. 2025 г. |
28Наблюдать | CVE-2025-61907Эксплойта нет | Icinga 2 API users could access restricted values in filter expressionsicinga · icinga · CWE-200 | Высокая7,1 | — | 0,4 % | 16 окт. 2025 г. |
28Наблюдать | CVE-2017-16933Эксплойта нет | etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local useicinga · icinga · CWE-732 | Высокая7,0 | — | 0,3 % | 24 нояб. 2017 г. |
- CVE-2022-2471657В плане
Path traversal in Icinga Web 2
ВысокаяCVSS 7,5Готовый эксплойтEPSS 89 %icinga · icinga web 28 мар. 2022 г.
- CVE-2012-609650В плане
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,
ВысокаяCVSS 7,5Готовый эксплойтEPSS 66 %nagios · nagios22 янв. 2013 г.
- CVE-2013-710840В плане
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow
СредняяCVSS 5,5Proof of conceptEPSS 60 %nagios · nagios15 янв. 2014 г.
- CVE-2024-4936940В плане
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
КритическаяCVSS 9,8Proof of conceptEPSS 3 %icinga · icinga12 нояб. 2024 г.
- CVE-2022-2471539Наблюдать
Arbitrary code execution for authenticated users in Icinga Web 2
ВысокаяCVSS 8,8Proof of conceptEPSS 15 %icinga · icinga web 28 мар. 2022 г.
- CVE-2018-1824939Наблюдать
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inf
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %icinga · icinga web 217 дек. 2018 г.
- CVE-2025-4805737Наблюдать
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
КритическаяCVSS 9,3Эксплойта нетEPSS 0 %icinga · icinga27 мая 2025 г.
- CVE-2021-3274336Наблюдать
Passwords used to access external services inadvertently exposed through API
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %icinga · icinga15 июл. 2021 г.
- CVE-2020-2966336Наблюдать
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %icinga · icinga15 дек. 2020 г.
- CVE-2021-3273935Наблюдать
Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %icinga · icinga15 июл. 2021 г.
- CVE-2023-3060735Наблюдать
icingaweb2-module-jira template and field configuration are susceptible to CSRF
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %icinga · icinga web jira integration5 июл. 2023 г.
- CVE-2024-2481935Наблюдать
icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRF
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %icinga · icingaweb2-module-incubator8 февр. 2024 г.
- CVE-2024-2482033Наблюдать
Icinga Director configuration is susceptible to Cross-Site Request Forgery
ВысокаяCVSS 8,3Эксплойта нетEPSS 0 %icinga · icinga8 февр. 2024 г.
- CVE-2018-653532Наблюдать
An issue was discovered in Icinga 2.x through 2.8.1.
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %icinga · icinga27 февр. 2018 г.
- CVE-2020-2436831Наблюдать
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %icinga · icinga web 219 авг. 2020 г.
- CVE-2012-344131Наблюдать
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga use
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %icinga · icinga25 авг. 2012 г.
- CVE-2020-1400431Наблюдать
An issue was discovered in Icinga2 before v2.12.0-rc1.
ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %icinga · icinga12 июн. 2020 г.
- CVE-2018-653331Наблюдать
An issue was discovered in Icinga 2.x through 2.8.1.
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %icinga · icinga27 февр. 2018 г.
- CVE-2017-1688231Наблюдать
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-roo
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %icinga · icinga18 нояб. 2017 г.
- CVE-2021-3769830Наблюдать
Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %icinga · icinga19 авг. 2021 г.
- CVE-2018-653230Наблюдать
An issue was discovered in Icinga 2.x through 2.8.1.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %icinga · icinga27 февр. 2018 г.
- CVE-2018-1825030Наблюдать
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navig
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %icinga · icinga web 217 дек. 2018 г.
- CVE-2025-6190828Наблюдать
Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference
ВысокаяCVSS 7,1Эксплойта нетEPSS 1 %icinga · icinga16 окт. 2025 г.
- CVE-2025-6190728Наблюдать
Icinga 2 API users could access restricted values in filter expressions
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %icinga · icinga16 окт. 2025 г.
- CVE-2017-1693328Наблюдать
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local use
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %icinga · icinga24 нояб. 2017 г.