CNNVD-202510-2317 Information

CNNVD ID

CNNVD-202510-2317

CVE-2025-61909

  • CNNVD Published: 2025-10-16

Description (Chinese)

Icinga 2是Icinga开源的一个监控系统。 Icinga 2 2.10.0版本至2.15.1之前版本、2.14.7版本和2.13.13版本存在安全漏洞,该漏洞源于safe-reload脚本和logrotate配置允许Icinga用户发送信号到其他进程,可能导致权限提升。

Description (English)

Icinga 2 is an Icinga open source monitoring system. There is a security loophole between Icinga version 2 2.10.0 and previous versions 2.15.1, Version 2.14.7 and Version 2.13.13, which originates from safe-reload scripts and logrotate configurations that allow Icinga users to send signals to other processes, which may lead to enhanced privileges.

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

Icinga

Published

2025-10-16

Last Modified

2026-02-24

References

https://github.com/Icinga/icinga2/commit/51ec73cbd922a76fc0f60e1d8d33acd7caa5d587 https://github.com/Icinga/icinga2/issues/10527 https://github.com/Icinga/icinga2/security/advisories/GHSA-pg6g-g99v-mw46 https://icinga.com/blog/releasing-icinga-2-v2-15-1-2-14-7-and-2-13-13-and-icinga-db-web-v1-2-3-and-1-1-4

Patch

https://icinga.com/docs/icinga-2/latest/doc/01-about/

Share on: