Vulnerability in the Icinga Web monitoring interface

Published patch releases Icinga Web 2.6.4, 2.7.4 and v2.8.2, providing a web interface for the monitoring system Icinga. The proposed updates address a critical vulnerability (CVE-2020-24368), allowing an unauthenticated attacker to access files on the server with the privileges of the Icinga Web process (usually the user under which the HTTP server or FPM runs).

For a successful attack, one of the third-party modules, supplied with images or icons, must be present. Notable among these modules are Icinga Business Process Modeling, Icinga Director,
Icinga Reporting, Maps Module, and Globe Module. These modules themselves have no vulnerabilities, but they are factors that facilitate an attack against Icinga Web.

The attack is carried out by sending HTTP GET or POST requests to a handler that serves images, which does not require an account to access. For example, if Icinga Web 2 is accessible as "/icingaweb2" and there is a businessprocess module installed in the directory /usr/share/icingaweb2/modules, to read the contents of the file /etc/os-release, a request can be sent as "GET /icingaweb2/static/img?module_name=businessprocess&file=../../../../../../etc/os-release".

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster