CVE-2025-27404

Source
https://nvd.nist.gov/vuln/detail/CVE-2025-27404
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-27404.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-27404
Aliases
  • GHSA-c6pg-h955-wf66
Downstream
Related
Published
2025-03-26T14:21:05Z
Modified
2025-10-20T20:30:48.243393Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Icinga Web 2 DOM-based XSS vulnerability
Details

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.

Database specific
{
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Git / github.com/icinga/icingaweb2

Affected ranges

Type
GIT
Repo
https://github.com/icinga/icingaweb2
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/icinga/icingaweb2
Events

Affected versions

v1.*

v1.0-11

v2.*

v2.0.0
v2.0.0-beta1
v2.0.0-beta2
v2.0.0-beta3
v2.0.0-rc1
v2.1.0
v2.1.1
v2.1.2
v2.10.0
v2.11.0
v2.11.1
v2.11.2
v2.11.3
v2.11.4
v2.12.0
v2.12.1
v2.12.2
v2.2.0
v2.3.0
v2.3.1
v2.3.2
v2.3.3
v2.3.4
v2.4.0
v2.4.0-2
v2.4.1
v2.5.0
v2.5.1
v2.5.2
v2.5.3
v2.6.0
v2.6.1
v2.6.2
v2.7.0
v2.7.1
v2.8.0
v2.8.0-rc1