CVE-2022-24715: Arbitrary code execution for authenticated users in Icinga Web 2
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Authenticated users, with access to the configuration, can create SSH resource files in unintended directories, leading to the execution of arbitrary code. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2. Users unable to upgrade should limit access to the Icinga Web 2 configuration.
Credit
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-24715?
CVE-2022-24715 is a vulnerability in Icinga Web 2 that allows authenticated users to execute arbitrary code by creating SSH resource files in unintended directories.
How does CVE-2022-24715 affect Icinga Web 2?
CVE-2022-24715 affects Icinga Web 2 versions up to 2.9.6, allowing authenticated users with access to the configuration to execute arbitrary code.
What is the severity of CVE-2022-24715?
CVE-2022-24715 has a severity score of 8.8 (high).
How can I fix CVE-2022-24715?
To fix CVE-2022-24715, update Icinga Web 2 to version 2.8.6 or later.
Are there any references for CVE-2022-24715?
Yes, you can find references for CVE-2022-24715 at the following links: [Exploit-DB](https://www.exploit-db.com/exploits/51586), [Packet Storm Security](http://packetstormsecurity.com/files/173516/Icinga-Web-2.10-Remote-Code-Execution.html), and [GitHub](https://github.com/Icinga/icingaweb2/commit/a06d915467ca943a4b406eb9587764b8ec34cafb).