CVE-2025-27406: Icinga Reporting Stored XSS leads to SSRF
Icinga Reporting is the central component for reporting related functionality in the monitoring web frontend and framework Icinga Web 2. A vulnerability present in versions 0.10.0 through 1.0.2 allows to set up a template that allows to embed arbitrary Javascript. This enables the attacker to act on behalf of the user, if the template is being previewed; and act on behalf of the headless browser, if a report using the template is printed to PDF. This issue has been resolved in version 1.0.3 of Icinga Reporting. As a workaround, review all templates and remove suspicious settings.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Icinga Reportingto a version that resolves this vulnerability.Fixed in 1.0.3 - Configuration
As a workaround for versions 0.10.0 through 1.0.2, review all Icinga Reporting templates and remove any suspicious settings that could embed/trigger arbitrary JavaScript.
Icinga Reporting templates suspicious settings = removed
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27406?
CVE-2025-27406 is classified as a medium severity vulnerability due to its potential to execute arbitrary JavaScript through template setups.
How do I fix CVE-2025-27406?
To fix CVE-2025-27406, upgrade Icinga Reporting to version 1.0.3 or later.
What versions are affected by CVE-2025-27406?
CVE-2025-27406 affects Icinga Reporting versions from 0.10.0 to 1.0.2.
What is the nature of the vulnerability in CVE-2025-27406?
The vulnerability in CVE-2025-27406 allows for the embedding of arbitrary JavaScript due to improper template handling.
Is there a workaround for CVE-2025-27406 before upgrading?
There are no known workarounds for CVE-2025-27406, and upgrading is recommended to mitigate the risk.