Information Disclosure in Icinga DB Web by Icinga
CVE-2025-61789

5.3MEDIUM

Key Information:

Vendor

Icinga

Vendor
CVE Published:
16 October 2025

What is CVE-2025-61789?

A vulnerability in Icinga DB Web enables an authorized user to exploit custom variables in filters, which may lead to the unintentional exposure of sensitive values. In versions prior to 1.1.4 and 1.2.3, users could manipulate these variables protected by specific configurations, potentially compromising data integrity. Fixed versions correctly handle such variables, returning errors to prevent unauthorized access.

Affected Version(s)

icingadb-web < 1.1.4 < 1.1.4

icingadb-web >= 1.2.0, < 1.2.3 < 1.2.0, 1.2.3

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61789 : Information Disclosure in Icinga DB Web by Icinga