{"id":"openSUSE-SU-2022:0087-1","summary":"Security update for icingaweb2","details":"This update for icingaweb2 fixes the following issues:\n\nicingaweb2 was updated to 2.8.6\n\nThis is a security release.\n\n* Security Fixes\n\n- CVE-2022-24715: SSH resources allow arbitrary code execution for authenticated users (GHSA-v9mv-h52f-7g63 boo#1196911)\n- CVE-2022-24714: Unwanted disclosure of hosts and related data, linked to decommissioned services (GHSA-qcmg-vr56-x9wf boo#1196913)\n","modified":"2026-03-11T07:33:23.300410Z","published":"2022-03-21T11:10:01Z","related":["CVE-2022-24714","CVE-2022-24715"],"upstream":["CVE-2022-24714","CVE-2022-24715"],"references":[{"type":"ADVISORY","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/GD5VHZVF4AMQ5DW6XK7XLRC3VYZWQGZW/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196911"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196913"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-24714"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-24715"}],"affected":[{"package":{"name":"icingaweb2","ecosystem":"SUSE:Package Hub 12","purl":"pkg:rpm/suse/icingaweb2&distro=SUSE%20Package%20Hub%2012"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.8.6-15.1"}]}],"ecosystem_specific":{"binaries":[{"icingaweb2":"2.8.6-15.1","php-Icinga":"2.8.6-15.1","icingaweb2-vendor-HTMLPurifier":"2.8.6-15.1","icingaweb2-vendor-JShrink":"2.8.6-15.1","icingaweb2-vendor-Parsedown":"2.8.6-15.1","icingacli":"2.8.6-15.1","icingaweb2-common":"2.8.6-15.1","icingaweb2-vendor-dompdf":"2.8.6-15.1","icingaweb2-vendor-lessphp":"2.8.6-15.1","icingaweb2-vendor-zf1":"2.8.6-15.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2022:0087-1.json"}}],"schema_version":"1.7.5"}