CVE-2025-61907

Name
CVE-2025-61907
Description
Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
MISC https://github.com/Icinga/icinga2/commit/56255ac7a689b9e198742d2fca6f7459a54c85a3
CONFIRM https://github.com/Icinga/icinga2/security/advisories/GHSA-gg32-w9rm-vp2v

Match rules

CPE URI Source package Min version Max version
icinga2 >= 2.15.0 < 2.15.1
icinga2 >= 2.14.0 < 2.14.7
icinga2 >= 2.4.0 < 2.13.13
cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* icinga >= 2.4.0 < 2.13.13
cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:* icinga >= 2.14.0 < 2.14.7
cpe:2.3:a:icinga:icinga:2.15.0:*:*:*:*:*:*:* icinga == None == 2.15.0

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
icinga2 edge-community 2.15.0-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 edge-community 2.14.5-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 edge-community 2.14.5-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 edge-community 2.14.3-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 edge-community 2.13.1-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 edge-community 2.11.3-r1 None possibly vulnerable
icinga2 3.22-community 2.14.5-r1 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 3.22-community 2.14.3-r0 Francesco Colista <fcolista@alpinelinux.org> possibly vulnerable
icinga2 3.22-community 2.13.1-r0 None possibly vulnerable
icinga2 3.22-community 2.11.3-r1 None possibly vulnerable