CVE-2025-23203

Name
CVE-2025-23203
Description
Icinga Director is an Icinga config deployment tool. A Security vulnerability has been found starting in version 1.0.0 and prior to 1.10.4 and 1.11.4 on several director endpoints of REST API. To reproduce this vulnerability an authenticated user with permission to access the Director is required (plus api access with regard to the api endpoints). And even though some of these Icinga Director users are restricted from accessing certain objects, are able to retrieve information related to them if their name is known. This makes it possible to change the configuration of these objects by those Icinga Director users restricted from accessing them. This results in further exploitation, data breaches and sensitive information disclosure. Affected endpoints include icingaweb2/director/service, if the host name is left out of the query; icingaweb2/directore/notification; icingaweb2/director/serviceset; and icingaweb2/director/scheduled-downtime. In addition, the endpoint `icingaweb2/director/services?host=filteredHostName` returns a status code 200 even though the services for the host is filtered. This in turn lets the restricted user know that the host `filteredHostName` exists even though the user is restricted from accessing it. This could again result in further exploitation of this information and data breaches. Icinga Director has patches in versions 1.10.4 and 1.11.4. If upgrading is not feasible, disable the director module for the users other than admin role for the time being.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/Icinga/icingaweb2-module-director/releases/tag/v1.10.3
MISC https://github.com/Icinga/icingaweb2-module-director/releases/tag/v1.11.3
CONFIRM https://github.com/Icinga/icingaweb2-module-director/security/advisories/GHSA-3233-ggc5-m3qg
security-advisories@github.com https://github.com/Icinga/icingaweb2-module-director/commit/3fcb20178ff1722329bf8689795e6cc8e53a9978
security-advisories@github.com https://github.com/Icinga/icingaweb2-module-director/commit/8d9ecf3b0a852aa2a756c518ef4f29db9ca0f9ee
security-advisories@github.com https://github.com/Icinga/icingaweb2-module-director/releases/tag/v1.10.4
security-advisories@github.com https://github.com/Icinga/icingaweb2-module-director/releases/tag/v1.11.4

Match rules

CPE URI Source package Min version Max version
icingaweb2-module-director >= 1.0.0 < 1.10.3
icingaweb2-module-director >= 1.11.0 < 1.11.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
icingaweb2-module-director edge-community 1.11.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icingaweb2-module-director 3.22-community 1.11.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable