Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.
Metrics
Affected Vendors & Products
References
History
Thu, 16 Oct 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Oct 2025 17:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13. | |
Title | Icinga 2 API users could access restricted values in filter expressions | |
Weaknesses | CWE-200 CWE-204 CWE-749 |
|
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-16T19:23:30.055Z
Reserved: 2025-10-03T22:21:59.613Z
Link: CVE-2025-61907

Updated: 2025-10-16T18:29:50.456Z

Status : Received
Published: 2025-10-16T18:15:37.820
Modified: 2025-10-16T18:15:37.820
Link: CVE-2025-61907

No data.

No data.