KEVIntel
7.5
CVSS
High

CVE-2022-24716

PUBLISHED

Path traversal in Icinga Web 2

Exploited in the wild PoC available Remote Low complexity No user interaction
Vendor
Icinga
Product
icingaweb2
Published
Mar 08, 2022
EPSS
93.2% · 100% pctl

Automate this intelligence with the Pro API

Everything on this page — CVSS, EPSS, exploit status, PoCs, scanner integrations, mentions, tags, and immediate honeypot sensor data — is available programmatically for VM, SOC, and CTI workflows.

Description

Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials. This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.

nuclei_scanner

Weaknesses (CWE)

  • The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

CVSS scores

CVSS v3.1 7.5 High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVSS v2.0 5.0 Medium

AV:N/AC:L/Au:N/C:P/I:N/A:N

Exploitation status

Exploited in the wild

Recorded 2026-06-04 00:00:00 UTC · Source

Proof of concept available

Recorded 2023-03-19 20:41:46 UTC · Source

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
The Shadowserver (via CIRCL) First 2026-06-04 00:00 UTC

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

doosec101/CVE-2022-24716

github · Created 2023-03-27 02:22:23 UTC · 3 stars

Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10

joaoviictorti/CVE-2022-24716

github · Created 2023-03-20 02:25:55 UTC · 6 stars

CVE-2022-24716 (Arbitrary File Disclosure Icingaweb2)

JacobEbben/CVE-2022-24716

github · Created 2023-03-19 20:41:46 UTC · 13 stars

Arbitrary File Disclosure Vulnerability in Icinga Web 2 <2.8.6, <2.9.6, <2.10

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Proof of Concept Exploit Available

  • Detected by Nuclei

  • Added to KEVIntel