DEBIAN-CVE-2025-27404

Source
https://security-tracker.debian.org/tracker/CVE-2025-27404
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-27404.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2025-27404
Upstream
Published
2025-03-26T15:16:14Z
Modified
2026-09-01T20:05:45Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.

References

Affected packages

Debian:12 / icingaweb2

Package

Name
icingaweb2
Purl
pkg:deb/debian/icingaweb2?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.11.4-2
2.11.4-2+deb12u1
2.11.4-3
2.12.0-1~exp1
2.12.0-1
2.12.1-1
2.12.2-1
2.12.4-1
2.12.4-2
2.12.5-1~exp1
2.12.5-1
2.12.6-1
2.13.0-1
2.13.1-1
2.14.0-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-27404.json"

Debian:13 / icingaweb2

Package

Name
icingaweb2
Purl
pkg:deb/debian/icingaweb2?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-27404.json"

Debian:14 / icingaweb2

Package

Name
icingaweb2
Purl
pkg:deb/debian/icingaweb2?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.12.4-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2025-27404.json"