openSUSE-SU-2022:0087-1
Dashboard / Vulnerabilities / openSUSE-SU-2022:0087-1
openSUSE-SU-2022:0087-1
Summary: Security update for icingaweb2
Details: This update for icingaweb2 fixes the following issues: icingaweb2 was updated to 2.8.6 This is a security release. * Security Fixes - CVE-2022-24715: SSH resources allow arbitrary code execution for authenticated users (GHSA-v9mv-h52f-7g63 boo#1196911) - CVE-2022-24714: Unwanted disclosure of hosts and related data, linked to decommissioned services (GHSA-qcmg-vr56-x9wf boo#1196913)
References: https://lists.opensuse.org/archives/list/[email protected]/thread/GD5VHZVF4AMQ5DW6XK7XLRC3VYZWQGZW/, https://bugzilla.suse.com/1196911, https://bugzilla.suse.com/1196913, https://www.suse.com/security/cve/CVE-2022-24714, https://www.suse.com/security/cve/CVE-2022-24715
Affected packages
Package
Name: icingaweb2
Purl: pkg:rpm/suse/icingaweb2&distro=SUSE%20Package%20Hub%2012
Affected ranges
Type: ECOSYSTEM
Events:
