CVE-2022-24716

HIGH EXPLOITED NUCLEI

Icinga Web 2 <2.9.5 - Info Disclosure

Title source: llm

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

Exploits (9)

nomisec WORKING POC 13 stars
by JacobEbben · infoleak
https://github.com/JacobEbben/CVE-2022-24716
nomisec WORKING POC 3 stars
by doosec101 · infoleak
https://github.com/doosec101/CVE-2022-24716
nomisec WORKING POC
by gmh5225 · poc
https://github.com/gmh5225/CVE-2022-24716
nomisec WORKING POC
by gmh5225 · infoleak
https://github.com/gmh5225/CVE-2022-24716-2
nomisec WORKING POC
by pumpkinpiteam · infoleak
https://github.com/pumpkinpiteam/CVE-2022-24716
nomisec WORKING POC
by antisecc · infoleak
https://github.com/antisecc/CVE-2022-24716
metasploit WORKING POC
by h00die, Jacob Ebben, Thomas Chauchefoin · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/icinga_static_library_file_directory_traversal.rb
exploitdb WORKING POC
by Jacob Ebben · pythonwebappsphp
https://www.exploit-db.com/exploits/51329

Nuclei Templates (1)

Icinga Web 2 - Arbitrary File Disclosure
HIGHby DhiyaneshDK
Shodan: title:"Icinga" || http.title:"icinga" || http.title:"icinga web 2 login"
FOFA: title="icinga web 2 login" || title="icinga"

Scores

CVSS v3 7.5
EPSS 0.9318
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploitation Intel

VulnCheck KEV 2024-01-22

Classification

CWE
CWE-22
Status published

Affected Products (1)

icinga/icinga_web_2 < 2.9.6

Timeline

Published Mar 08, 2022
Tracked Since Feb 18, 2026