Icinga Web 2 Open Redirect Vulnerability

Vulnerability

An open redirect vulnerability has been identified in Icinga Web 2 versions prior to 2.11.5 and 2.12.2. This vulnerability allows an attacker to create a URL that, when clicked by an authenticated user, redirects them to a location of the attacker's choosing. The issue arises from improper handling of URL redirection in the backend.

Impact

Exploitation of this vulnerability allows for open redirection, where users can be sent to any external location, potentially leading to phishing attacks or other malicious activities.

Remediation

Users are advised to upgrade to Icinga Web 2 versions 2.11.5 or 2.12.3, both of which address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
0.8
exploitability
6.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.