Icinga Web 2 before 2.6.2 allows injection of PHP ini-file directives via vectors involving environment variables as the channel to send information to the attacker, such as a name=${PATH}${APACHERUNDIR}${APACHERUNUSER} parameter to /icingaweb2/navigation/add or /icingaweb2/dashboard/new-dashlet.
{
"binaries": [
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingacli"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.4.1-1ubuntu0.1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.7.3-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.7.3-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.7.3-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.9.5-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.9.5-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.9.5-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.1-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.1-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.1-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.2-1",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.2-1",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.2-1",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.2-1",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.2-1",
"binary_name": "php-icinga"
}
]
}{
"binaries": [
{
"binary_version": "2.12.4-2",
"binary_name": "icingacli"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2-common"
},
{
"binary_version": "2.12.4-2",
"binary_name": "icingaweb2-module-monitoring"
},
{
"binary_version": "2.12.4-2",
"binary_name": "php-icinga"
}
]
}