Skip to content

Unwanted disclosure of hosts and related data, linked to decommissioned services

Moderate
nilmerg published GHSA-qcmg-vr56-x9wf Mar 8, 2022

Package

icingaweb2 (Icinga)

Affected versions

<=2.9.5

Patched versions

2.8.6, 2.9.6 and 2.10

Description

Impact

Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to the following content:

  • Contactgroups
  • Contacts
  • Hosts
  • Host events
  • Host comments
  • Host downtimes
  • Hostgroups

Note that this only applies if a role has implicitly permitted access to hosts, due to permitted access to at least one of their services. If access to a host is permitted by other means, no sensible information has been disclosed to unauthorized users.

Patches

This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2.

For more information

If you have any questions or comments about this advisory, ask for assistance on the forums.

Severity

Moderate

CVE ID

CVE-2022-24714

Weaknesses

No CWEs