Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.
References
Configurations
No configuration.
History
27 Mar 2025, 16:45
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
26 Mar 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-26 17:15
Updated : 2025-03-27 16:45
NVD link : CVE-2025-30164
Mitre link : CVE-2025-30164
CVE.ORG link : CVE-2025-30164
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')