Icinga kayıtları
icinga üreticisine ait 49 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 2 · %4,1
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %85,7
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-352 Cross-Site Request Forgery (CSRF)5
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer3
- CWE-295 Improper Certificate Validation3
- CWE-732 Incorrect Permission Assignment for Critical Resource3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
49 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
57Planlayın | CVE-2022-24716Silahlaştırılmış | Path traversal in Icinga Web 2icinga · icinga web 2 · CWE-22 | Yüksek7,5 | — | %89,4 | 8 Mar 2022 |
50Planlayın | CVE-2012-6096Silahlaştırılmış | Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,nagios · nagios · CWE-119 | Yüksek7,5 | — | %66,5 | 22 Oca 2013 |
40Planlayın | CVE-2013-7108Kavram kanıtı | Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allownagios · nagios · CWE-20 | Orta5,5 | — | %59,5 | 15 Oca 2014 |
40Planlayın | CVE-2024-49369Kavram kanıtı | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connectionsicinga · icinga · CWE-295 | Kritik9,8 | — | %2,9 | 12 Kas 2024 |
39İzleyin | CVE-2022-24715Kavram kanıtı | Arbitrary code execution for authenticated users in Icinga Web 2icinga · icinga web 2 · CWE-22 | Yüksek8,8 | — | %14,7 | 8 Mar 2022 |
39İzleyin | CVE-2018-18249İstismar yok | Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inficinga · icinga web 2 · CWE-94 | Kritik9,8 | — | %1,5 | 17 Ara 2018 |
37İzleyin | CVE-2025-48057İstismar yok | Icinga 2 certificate renewal might incorrectly renew an invalid certificateicinga · icinga · CWE-296 | Kritik9,3 | — | %0,4 | 27 May 2025 |
36İzleyin | CVE-2021-32743İstismar yok | Passwords used to access external services inadvertently exposed through APIicinga · icinga · CWE-202 | Yüksek8,8 | — | %1,8 | 15 Tem 2021 |
36İzleyin | CVE-2020-29663İstismar yok | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring icinga · icinga · CWE-295 | Kritik9,1 | — | %1,6 | 15 Ara 2020 |
35İzleyin | CVE-2021-32739İstismar yok | Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identitiesicinga · icinga · CWE-267 | Yüksek8,8 | — | %1,1 | 15 Tem 2021 |
35İzleyin | CVE-2023-30607İstismar yok | icingaweb2-module-jira template and field configuration are susceptible to CSRFicinga · icinga web jira integration · CWE-352 | Yüksek8,8 | — | %0,3 | 5 Tem 2023 |
35İzleyin | CVE-2024-24819İstismar yok | icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRFicinga · icingaweb2-module-incubator · CWE-352 | Yüksek8,8 | — | %0,3 | 8 Şub 2024 |
33İzleyin | CVE-2024-24820İstismar yok | Icinga Director configuration is susceptible to Cross-Site Request Forgeryicinga · icinga · CWE-352 | Yüksek8,3 | — | %0,4 | 8 Şub 2024 |
32İzleyin | CVE-2018-6535İstismar yok | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga | Yüksek8,1 | — | %1,3 | 27 Şub 2018 |
31İzleyin | CVE-2020-24368İstismar yok | Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitraryicinga · icinga web 2 · CWE-22 | Yüksek7,5 | — | %3,3 | 19 Ağu 2020 |
31İzleyin | CVE-2012-3441İstismar yok | The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga useicinga · icinga · CWE-264 | Yüksek7,5 | — | %2,4 | 25 Ağu 2012 |
31İzleyin | CVE-2020-14004İstismar yok | An issue was discovered in Icinga2 before v2.12.0-rc1.icinga · icinga · CWE-59 | Yüksek7,8 | — | %0,7 | 12 Haz 2020 |
31İzleyin | CVE-2018-6533İstismar yok | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga | Yüksek7,8 | — | %0,4 | 27 Şub 2018 |
31İzleyin | CVE-2017-16882İstismar yok | Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-rooicinga · icinga · CWE-732 | Yüksek7,8 | — | %0,3 | 18 Kas 2017 |
30İzleyin | CVE-2021-37698İstismar yok | Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writericinga · icinga · CWE-295 | Yüksek7,5 | — | %1,4 | 19 Ağu 2021 |
30İzleyin | CVE-2018-6532İstismar yok | An issue was discovered in Icinga 2.x through 2.8.1.icinga · icinga · CWE-400 | Yüksek7,5 | — | %1,4 | 27 Şub 2018 |
30İzleyin | CVE-2018-18250İstismar yok | Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigicinga · icinga web 2 · CWE-74 | Yüksek7,5 | — | %1,0 | 17 Ara 2018 |
28İzleyin | CVE-2025-61908İstismar yok | Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Referenceicinga · icinga · CWE-476 | Yüksek7,1 | — | %0,5 | 16 Eki 2025 |
28İzleyin | CVE-2025-61907İstismar yok | Icinga 2 API users could access restricted values in filter expressionsicinga · icinga · CWE-200 | Yüksek7,1 | — | %0,4 | 16 Eki 2025 |
28İzleyin | CVE-2017-16933İstismar yok | etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local useicinga · icinga · CWE-732 | Yüksek7,0 | — | %0,3 | 24 Kas 2017 |
- CVE-2022-2471657Planlayın
Path traversal in Icinga Web 2
YüksekCVSS 7,5SilahlaştırılmışEPSS %89icinga · icinga web 28 Mar 2022
- CVE-2012-609650Planlayın
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga 1.6.x before 1.6.2,
YüksekCVSS 7,5SilahlaştırılmışEPSS %66nagios · nagios22 Oca 2013
- CVE-2013-710840Planlayın
Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow
OrtaCVSS 5,5Kavram kanıtıEPSS %60nagios · nagios15 Oca 2014
- CVE-2024-4936940Planlayın
Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections
KritikCVSS 9,8Kavram kanıtıEPSS %3icinga · icinga12 Kas 2024
- CVE-2022-2471539İzleyin
Arbitrary code execution for authenticated users in Icinga Web 2
YüksekCVSS 8,8Kavram kanıtıEPSS %15icinga · icinga web 28 Mar 2022
- CVE-2018-1824939İzleyin
Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send inf
KritikCVSS 9,8İstismar yokEPSS %1icinga · icinga web 217 Ara 2018
- CVE-2025-4805737İzleyin
Icinga 2 certificate renewal might incorrectly renew an invalid certificate
KritikCVSS 9,3İstismar yokEPSS %0icinga · icinga27 May 2025
- CVE-2021-3274336İzleyin
Passwords used to access external services inadvertently exposed through API
YüksekCVSS 8,8İstismar yokEPSS %2icinga · icinga15 Tem 2021
- CVE-2020-2966336İzleyin
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring
KritikCVSS 9,1İstismar yokEPSS %2icinga · icinga15 Ara 2020
- CVE-2021-3273935İzleyin
Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities
YüksekCVSS 8,8İstismar yokEPSS %1icinga · icinga15 Tem 2021
- CVE-2023-3060735İzleyin
icingaweb2-module-jira template and field configuration are susceptible to CSRF
YüksekCVSS 8,8İstismar yokEPSS %0icinga · icinga web jira integration5 Tem 2023
- CVE-2024-2481935İzleyin
icingaweb2-module-incubator base implementation for HTML forms is susceptible to CSRF
YüksekCVSS 8,8İstismar yokEPSS %0icinga · icingaweb2-module-incubator8 Şub 2024
- CVE-2024-2482033İzleyin
Icinga Director configuration is susceptible to Cross-Site Request Forgery
YüksekCVSS 8,3İstismar yokEPSS %0icinga · icinga8 Şub 2024
- CVE-2018-653532İzleyin
An issue was discovered in Icinga 2.x through 2.8.1.
YüksekCVSS 8,1İstismar yokEPSS %1icinga · icinga27 Şub 2018
- CVE-2020-2436831İzleyin
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary
YüksekCVSS 7,5İstismar yokEPSS %3icinga · icinga web 219 Ağu 2020
- CVE-2012-344131İzleyin
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga use
YüksekCVSS 7,5İstismar yokEPSS %2icinga · icinga25 Ağu 2012
- CVE-2020-1400431İzleyin
An issue was discovered in Icinga2 before v2.12.0-rc1.
YüksekCVSS 7,8İstismar yokEPSS %1icinga · icinga12 Haz 2020
- CVE-2018-653331İzleyin
An issue was discovered in Icinga 2.x through 2.8.1.
YüksekCVSS 7,8İstismar yokEPSS %0icinga · icinga27 Şub 2018
- CVE-2017-1688231İzleyin
Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-roo
YüksekCVSS 7,8İstismar yokEPSS %0icinga · icinga18 Kas 2017
- CVE-2021-3769830İzleyin
Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer
YüksekCVSS 7,5İstismar yokEPSS %1icinga · icinga19 Ağu 2021
- CVE-2018-653230İzleyin
An issue was discovered in Icinga 2.x through 2.8.1.
YüksekCVSS 7,5İstismar yokEPSS %1icinga · icinga27 Şub 2018
- CVE-2018-1825030İzleyin
Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navig
YüksekCVSS 7,5İstismar yokEPSS %1icinga · icinga web 217 Ara 2018
- CVE-2025-6190828İzleyin
Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference
YüksekCVSS 7,1İstismar yokEPSS %1icinga · icinga16 Eki 2025
- CVE-2025-6190728İzleyin
Icinga 2 API users could access restricted values in filter expressions
YüksekCVSS 7,1İstismar yokEPSS %0icinga · icinga16 Eki 2025
- CVE-2017-1693328İzleyin
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local use
YüksekCVSS 7,0İstismar yokEPSS %0icinga · icinga24 Kas 2017