Information Disclosure Vulnerability in Icinga Director by Icinga
CVE-2025-23203
What is CVE-2025-23203?
Icinga Director, a tool for Icinga configuration deployment, has a vulnerability that affects various versions prior to 1.10.3 and 1.11.1. Authenticated users, despite restrictions, can exploit the REST API to access and manipulate configurations of objects not normally accessible to them. This occurs through various endpoints, allowing restricted users to determine the existence of certain objects if they know the object’s name, which can lead to unauthorized data disclosure and potential exploitation. Patches are available in versions 1.10.3 and 1.11.1. For immediate protection, it is advisable to limit access to the director module to admin roles only.
Affected Version(s)
icingaweb2-module-director >= 1.0.0, < 1.10.4 < 1.0.0, 1.10.4
icingaweb2-module-director >= 1.11.0, < 1.11.4 < 1.11.0, 1.11.4
