CVE-2025-30164

Source
https://cve.org/CVERecord?id=CVE-2025-30164
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-30164.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2025-30164
Aliases
  • GHSA-8r73-6686-wv8q
Downstream
Related
Published
2025-03-26T16:13:26.590Z
Modified
2026-05-28T03:54:16.463846837Z
Severity
  • 4.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N CVSS Calculator
Summary
Icinga Web 2 has open redirect on login page
Details

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/30xxx/CVE-2025-30164.json",
    "cwe_ids": [
        "CWE-601"
    ],
    "cna_assigner": "GitHub_M"
}
References

Affected packages

Git / github.com/icinga/icingaweb2

Affected ranges

Type
GIT
Repo
https://github.com/icinga/icingaweb2
Events

Affected versions

v2.*
v2.12.0
v2.12.1
v2.12.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2025-30164.json"