First published: Wed Jan 15 2014(Updated: )
Cross-site request forgery (CSRF) vulnerability in cmd.cgi in Icinga 1.8.5, 1.9.4, 1.10.2, and earlier allows remote attackers to hijack the authentication of users for unspecified commands via unspecified vectors, as demonstrated by bypassing authentication requirements for CVE-2013-7106.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga | <=1.10.2 | |
Icinga Icinga | =0.8.0 | |
Icinga Icinga | =0.8.1 | |
Icinga Icinga | =0.8.2 | |
Icinga Icinga | =0.8.3 | |
Icinga Icinga | =0.8.4 | |
Icinga Icinga | =1.0 | |
Icinga Icinga | =1.0-rc1 | |
Icinga Icinga | =1.0.1 | |
Icinga Icinga | =1.0.2 | |
Icinga Icinga | =1.0.3 | |
Icinga Icinga | =1.2.0 | |
Icinga Icinga | =1.2.1 | |
Icinga Icinga | =1.3.0 | |
Icinga Icinga | =1.3.1 | |
Icinga Icinga | =1.4.0 | |
Icinga Icinga | =1.4.1 | |
Icinga Icinga | =1.6.0 | |
Icinga Icinga | =1.6.1 | |
Icinga Icinga | =1.6.2 | |
Icinga Icinga | =1.7.0 | |
Icinga Icinga | =1.7.1 | |
Icinga Icinga | =1.7.2 | |
Icinga Icinga | =1.7.3 | |
Icinga Icinga | =1.7.4 | |
Icinga Icinga | =1.8.0 | |
Icinga Icinga | =1.8.1 | |
Icinga Icinga | =1.8.2 | |
Icinga Icinga | =1.8.3 | |
Icinga Icinga | =1.8.4 | |
Icinga Icinga | =1.8.5 | |
Icinga Icinga | =1.9.0 | |
Icinga Icinga | =1.9.1 | |
Icinga Icinga | =1.9.2 | |
Icinga Icinga | =1.9.3 | |
Icinga Icinga | =1.9.4 | |
Icinga Icinga | =1.10.0 | |
Icinga Icinga | =1.10.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.