CVE-2025-61907

Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 through 2.15.0, filter expressions provided to the various /v1/objects endpoints could access variables or objects that would otherwise be inaccessible for the user. This allows authenticated API users to learn information that should be hidden from them, including global variables not permitted by the variables permission and objects not permitted by the corresponding objects/query permissions. The vulnerability is fixed in versions 2.15.1, 2.14.7, and 2.13.13.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*
cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*
cpe:2.3:a:icinga:icinga:2.15.0:*:*:*:*:*:*:*

History

26 Nov 2025, 15:04

Type Values Removed Values Added
CPE cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*
cpe:2.3:a:icinga:icinga:2.15.0:*:*:*:*:*:*:*
First Time Icinga
Icinga icinga
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
References () https://github.com/Icinga/icinga2/commit/56255ac7a689b9e198742d2fca6f7459a54c85a3 - () https://github.com/Icinga/icinga2/commit/56255ac7a689b9e198742d2fca6f7459a54c85a3 - Patch
References () https://github.com/Icinga/icinga2/security/advisories/GHSA-gg32-w9rm-vp2v - () https://github.com/Icinga/icinga2/security/advisories/GHSA-gg32-w9rm-vp2v - Patch, Vendor Advisory

Information

Published : 2025-10-16 18:15

Updated : 2025-11-26 15:04


NVD link : CVE-2025-61907

Mitre link : CVE-2025-61907

CVE.ORG link : CVE-2025-61907


JSON object : View

Products Affected

icinga

  • icinga
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-204

Observable Response Discrepancy

CWE-749

Exposed Dangerous Method or Function