CVE-2022-24716
HIGH 7.5EPSS 89.4%
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 89.38% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-22
- Published
- 2022-03-08
- Updated
- 2025-04-23
Proof-of-concept exploits (6)
- antisecc/CVE-2022-247160★ · 2023-05-20
- doosec101/CVE-2022-247163★ · 2023-03-27
- pumpkinpiteam/CVE-2022-247160★ · 2023-03-26
- 0x0Jackal/CVE-2022-24716
- gmh5225/CVE-2022-24716
- gmh5225/CVE-2022-24716-2