← Back to browse · API

CVE-2022-24716

Severity
HIGH
CVSS
7.5
EPSS
0.89378
Risk score
61.28
CISA KEV
No
PoC
No
Published
2022-03-08
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2022-29577
Products
Icinga:icingaweb2 2.9.0, < 2.9.6
Sources
euvd EUVD-2022-29577

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

References