Medium severity5.3NVD Advisory· Published Oct 16, 2025· Updated Jun 17, 2026
CVE-2025-61789
CVE-2025-61789
Description
Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:icinga:icinga_db_web:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:icinga:icinga_db_web:*:*:*:*:*:*:*:*range: <1.1.4
- (no CPE)range: <1.1.4, <1.2.3
- (no CPE)range: < 1.1.4
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.