漏洞标题
查询ApiListener对象的结果包括票证盐,这反过来又允许窃取(权限更高的)身份。
漏洞描述信息
查询ApiListener对象的结果包括票证盐,这反过来又可以让您窃取(权限更高的)身份。
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
N/A
漏洞标题
Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities
漏洞描述信息
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attributes of all config objects including `ticket_salt` of `ApiListener`. This salt is enough to compute a ticket for every possible common name (CN). A ticket, the master node's certificate, and a self-signed certificate are enough to successfully request the desired certificate from Icinga. That certificate may in turn be used to steal an endpoint or API user's identity. Versions 2.12.5 and 2.11.10 both contain a fix the vulnerability. As a workaround, one may either specify queryable types explicitly or filter out ApiListener objects.
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
漏洞类别
特权定义了不安全动作
漏洞标题
Icinga 安全漏洞
漏洞描述信息
Icinga是德国Icinga公司的一套可扩展的服务器、网络资源监控系统。 Icinga 存在安全漏洞,该漏洞源于Icinga从2.4.0到2.12.4版本允许通过身份验证的API用户存在权限升级问题。攻击者可利用该漏洞查看所有配置对象的大多数属性,包括ApiListener 的ticket salt。
CVSS信息
N/A
漏洞类别
其他