Directory Traversal Affecting icingaweb2 package, versions <2.8.2-1


Severity

Recommended
0.0
high
0
10

Snyk's Security Team recommends NVD's CVSS assessment. Learn more

Threat Intelligence

EPSS
3.28% (87th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-DEBIANUNSTABLE-ICINGAWEB2-608208
  • published22 Aug 2020
  • disclosed19 Aug 2020

Introduced: 19 Aug 2020

CVE-2020-24368  (opens in a new tab)
CWE-22  (opens in a new tab)

How to fix?

Upgrade Debian:unstable icingaweb2 to version 2.8.2-1 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream icingaweb2 package and not the icingaweb2 package as distributed by Debian. See How to fix? for Debian:unstable relevant fixed versions and status.

Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.

CVSS Base Scores

version 3.1