VYPR
Vendor

Icinga

Products
14
CVEs
58
Across products
86
Status
Private

Products

14

Recent CVEs

58
View all 58 CVEs →
  • CVE-2018-18249CriDec 17, 2018
    risk 0.64cvss 9.8epss 0.01

    Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}_${APACHE_RUN_DIR}_${APACHE_RUN_USER} parameter to /icingaweb2/navigation/add or…

  • CVE-2020-29663CriDec 15, 2020
    risk 0.59cvss 9.1epss 0.02

    Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.

  • CVE-2026-61550CriSep 18, 2026
    risk 0.57cvss 9.8epss 0.01

    Icinga 2 is an open source monitoring system. From 2.8 until 2.14.9, 2.15.4, and 2.16.2, certificate update JSON-RPC message handling does not validate that the sender is a trusted endpoint. An unauthenticated network attacker able to connect to TCP port 5665 can replace the…

  • CVE-2021-32743HigJul 15, 2021
    risk 0.57cvss 8.8epss 0.02

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require…

  • CVE-2021-32739HigJul 15, 2021
    risk 0.57cvss 8.8epss 0.01

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API…

  • CVE-2018-6535HigFeb 27, 2018
    risk 0.53cvss 8.1epss 0.01

    An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.

  • CVE-2020-14004HigJun 12, 2020
    risk 0.51cvss 7.8epss 0.01

    An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by…

  • CVE-2018-6533HigFeb 27, 2018
    risk 0.51cvss 7.8epss 0.00

    An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any…

  • CVE-2017-16882HigNov 18, 2017
    risk 0.51cvss 7.8epss 0.00

    Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and similarly can have etc/icinga.cfg owned by a non-root account), which allows local users to gain privileges by leveraging…

  • CVE-2026-61551HigSep 18, 2026
    risk 0.49cvss 8.6epss 0.01

    Icinga 2 is an open source monitoring system. Prior to 2.14.9, 2.15.4, and 2.16.2, parsing deeply nested JSON can exhaust the call stack because nesting depth is not bounded. The affected JSON parsing paths are reachable by unauthenticated network clients through the Icinga 2…

  • CVE-2025-27405HigMar 26, 2025
    risk 0.49cvss 7.6epss 0.00

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to…

  • CVE-2025-27404HigMar 26, 2025
    risk 0.49cvss 7.6epss 0.01

    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to…

  • CVE-2021-37698HigAug 19, 2021
    risk 0.49cvss 7.5epss 0.01

    Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the…

  • CVE-2020-24368HigAug 19, 2020
    risk 0.49cvss 7.5epss 0.03

    Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.

  • CVE-2018-18250HigDec 17, 2018
    risk 0.49cvss 7.5epss 0.01

    Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item.

  • CVE-2018-6532HigFeb 27, 2018
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.

  • CVE-2017-16933HigNov 24, 2017
    risk 0.46cvss 7.0epss 0.00

    etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

  • CVE-2026-42224HigMay 8, 2026
    risk 0.42cvss 7.6epss 0.00

    ipl/web is a set of common web components for php projects. Prior to versions 0.13.1 and 0.10.3, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared…

  • CVE-2025-27406HigMar 26, 2025
    risk 0.42cvss 7.6epss 0.00

    Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables…

  • CVE-2018-18246MedDec 17, 2018
    risk 0.42cvss 6.5epss 0.00

    Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.