Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 16 Oct 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 16 Oct 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used. | |
Title | Icinga DB Web hidden/protected custom variables are prone to filter enumeration | |
Weaknesses | CWE-204 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-16T18:03:11.988Z
Reserved: 2025-09-30T19:43:49.903Z
Link: CVE-2025-61789

Updated: 2025-10-16T18:03:08.103Z

Status : Received
Published: 2025-10-16T17:15:34.590
Modified: 2025-10-16T17:15:34.590
Link: CVE-2025-61789

No data.

No data.