URL Manipulation Vulnerability in Icinga Web 2 by Icinga
CVE-2025-30164
6.1MEDIUM
What is CVE-2025-30164?
A vulnerability exists in Icinga Web 2, an open-source web interface for monitoring solutions, that enables an attacker to craft a malicious URL. If an authenticated user accesses this link, they may inadvertently redirect their session to an arbitrary location, compromising the integrity of their browsing session. The issue has been addressed in versions 2.11.5 and 2.12.3 of Icinga Web 2. As of now, there are no known workarounds to mitigate this threat.
Affected Version(s)
icingaweb2 < 2.11.5 < 2.11.5
icingaweb2 >= 2.12.0, < 2.12.3 < 2.12.0, 2.12.3
