Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 11 Dec 2025 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icinga icinga Db Web
|
|
| CPEs | cpe:2.3:a:icinga:icinga_db_web:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Icinga icinga Db Web
|
Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Icinga
Icinga icinga Icinga icinga Web 2 |
|
| Vendors & Products |
Icinga
Icinga icinga Icinga icinga Web 2 |
Thu, 16 Oct 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 16 Oct 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Icinga DB Web provides a graphical interface for Icinga monitoring. Before 1.1.4 and 1.2.3, an authorized user with access to Icinga DB Web, can use a custom variable in a filter that is either protected by icingadb/protect/variables or hidden by icingadb/denylist/variables, to guess values assigned to it. Versions 1.1.4 and 1.2.3 respond with an error if such a custom variable is used. | |
| Title | Icinga DB Web hidden/protected custom variables are prone to filter enumeration | |
| Weaknesses | CWE-204 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-10-16T18:03:11.988Z
Reserved: 2025-09-30T19:43:49.903Z
Link: CVE-2025-61789
Updated: 2025-10-16T18:03:08.103Z
Status : Analyzed
Published: 2025-10-16T17:15:34.590
Modified: 2025-12-11T18:24:46.077
Link: CVE-2025-61789
No data.
OpenCVE Enrichment
Updated: 2025-10-21T09:39:58Z