First published: Sat Aug 25 2012(Updated: )
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga Web 2 | =1.7.1 |
https://git.icinga.org/?p=icinga-core.git;a=commitdiff;h=712813d3118a5b9e5a496179cab81dbe91f69d63
https://git.icinga.org/?p=icinga-core.git;a=commitdiff;h=dcd45fb6931c4abf710829bee21af09f842bc281
https://git.icinga.org/?p=icinga-doc.git;a=commitdiff;h=619a08ca1178144b8a3a5caafff32a2d3918edab
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-3441 is classified as a high severity vulnerability due to its potential to grant unauthorized access to sensitive databases.
To fix CVE-2012-3441, you should modify the database user permissions to restrict access to only necessary databases.
CVE-2012-3441 specifically affects Icinga version 1.7.1.
The implications of CVE-2012-3441 include the risk of icinga users accessing and manipulating other databases, potentially leading to data breaches.
Despite being discovered in 2012, CVE-2012-3441 can still pose a concern in environments that continue to run the vulnerable version of Icinga.