CVE-2020-24368: Path Traversal
Published Aug 19, 2020
·Updated
Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
Affected Software
9 affected componentsFixes available
debian/icingaweb2
2.6.2-3+deb10u12.8.2-22.11.4-2+deb12u12.12.0-1
debian/icingaweb2<=2.6.2-3, <=2.8.1-1, <=2.0.0~beta3-1
2.8.2-12.6.2-3+deb10u1
Icinga Icinga Web 2>=2.0.0<2.6.4
Icinga Icinga Web 2>=2.7.0<2.7.4
Icinga Icinga Web 2>=2.8.0<2.8.2
Debian Debian Linux=9.0
Debian Debian Linux=10
SUSE Package Hub
SUSE Linux Enterprise=12.0
Event History
Aug 19, 2020
CVE Published
via MITRE·02:25 PM
Data Sourced
via MITRE·02:25 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID of this security issue is CVE-2020-24368.
2
What is the severity level of CVE-2020-24368?
The severity level of CVE-2020-24368 is high, with a severity value of 7.5.
3
What is the affected software?
The affected software is Icinga Web2 versions 2.0.0 through 2.6.4, 2.7.4, and 2.8.2.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by accessing arbitrary files that are readable by the process running Icinga Web 2.
5
How can I fix CVE-2020-24368?
To fix CVE-2020-24368, update Icinga Web2 to versions 2.6.4, 2.7.4, or 2.8.2.