Skip to content

Path traversal in static library file requests for unauthenticated users

High
nilmerg published GHSA-5p3f-rh28-8frw Mar 8, 2022

Package

icingaweb2 (Icinga)

Affected versions

>= 2.9.0, <= 2.9.5

Patched versions

2.9.6 and 2.10

Description

Impact

Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including icingaweb2 configuration files with database credentials.

Patches

This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2.

Database credentials should be rotated.

Workarounds

Only allow trusted source IP addresses to access to the icingaweb2 instance and the database.

References

Further technical details will be disclosed on https://blog.sonarsource.com/tag/security after some time.

For more information

If you have any questions or comments about this advisory, you can contact:

  • The original reporters, by sending an email to vulnerability.research [at] sonarsource.com;
  • The maintainers, by asking for assistance on the forums

Severity

High

CVE ID

CVE-2022-24716

Weaknesses

No CWEs