FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

Icinga Web 2 -- directory traversal vulnerability

Affected packages
icingaweb2 <= 2.8.1

Details

VuXML ID f60561e7-e23e-11ea-be64-507b9d01076a
Discovery 2020-08-19
Entry 2020-08-19

Icinga development team reports:

CVE-2020-24368

Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.

References

CVE Name CVE-2020-24368
URL https://icinga.com/2020/08/19/icinga-web-security-release-v2-6-4-v2-7-4-and-v2-8-2/