Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.
| Software | From | Fixed in |
|---|---|---|
| icinga / icinga_web_2 | 2.0.0 | 2.6.4 |
| icinga / icinga_web_2 | 2.7.0 | 2.7.4 |
| icinga / icinga_web_2 | 2.8.0 | 2.8.2 |
| debian / debian_linux | 9.0 | 9.0.x |
| debian / debian_linux | 10 | 10.x |