CVE 7.1 HIGH

Icinga 2 API users could access restricted values in filter expressions_CVE-2025-61907

7.1 / 10
HIGH
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N

Description

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.

Basic Information

ID CVE-2025-61907
Source GitHub_M
Published Oct 16, 2025 at 17:11
Modified Oct 16, 2025 at 19:23

Affected Product

Vendor Icinga
Product icinga2
Version >= 2.15.0, < 2.15.1
Affected Versions Icinga icinga2 >= 2.15.0, < 2.15.1
Icinga icinga2 >= 2.14.0, < 2.14.7
Icinga icinga2 >= 2.4.0, < 2.13.13

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.