Debian Package Tracker
Register | Log in
Subscribe

icingaweb2

simple and responsive web interface for Icinga

Choose email to subscribe with

general
  • source: icingaweb2 (main)
  • version: 2.12.5-1
  • maintainer: Debian Nagios Maintainer Group (archive) (DMD)
  • uploaders: Markus Frosch [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.8.2-2
  • oldstable: 2.11.4-2+deb12u1
  • stable: 2.12.4-2
  • testing: 2.12.5-1
  • unstable: 2.12.5-1
versioned links
  • 2.8.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.11.4-2+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.4-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • icingacli
  • icingaweb2
  • icingaweb2-common
  • icingaweb2-module-doc
  • icingaweb2-module-monitoring
  • php-icinga
action needed
4 security issues in bookworm high

There are 4 open security issues in bookworm.

4 important issues:
  • CVE-2025-27404: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.
  • CVE-2025-27405: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.
  • CVE-2025-27609: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings. Any modern browser with a working CORS implementation also sufficiently guards against the vulnerability.
  • CVE-2025-30164: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.
Created: 2025-03-27 Last update: 2025-11-08 13:31
version in VCS is newer than in repository, is it time to upload? normal
vcswatch reports that this package seems to have a new changelog entry (version 2.12.5-2, distribution UNRELEASED) and new commits in its VCS. You should consider whether it's time to make an upload.

Here are the relevant commit messages:
commit ad8d0a34873db4665a2d62f8b41eb24908b72980
Author: Bas Couwenberg <sebastic@xs4all.nl>
Date:   Sat Oct 25 12:49:00 2025 +0200

    Use test-build-validate-cleanup instead of test-build-twice.

commit c5bd4d6f07e85b96cad7c2409fe89f5b5d50b69e
Author: Bas Couwenberg <sebastic@xs4all.nl>
Date:   Wed Oct 1 11:16:03 2025 +0200

    Revert "Drop Priority: optional, default since dpkg 1.22.13."
    
    This reverts commit 7bfcb9ca035dc0c06e7a05c5ef8c6f9607aa8f5e.

commit 7bfcb9ca035dc0c06e7a05c5ef8c6f9607aa8f5e
Author: Bas Couwenberg <sebastic@xs4all.nl>
Date:   Wed Oct 1 09:41:40 2025 +0200

    Drop Priority: optional, default since dpkg 1.22.13.

commit b75e31a081583f384561a025a7fac66362f1f366
Author: Bas Couwenberg <sebastic@xs4all.nl>
Date:   Wed Oct 1 09:00:03 2025 +0200

    Drop Rules-Requires-Root: no, default since dpkg 1.22.13.

commit 30312281dbc260347ce6507dcd8d3779c5c50acc
Author: Bas Couwenberg <sebastic@xs4all.nl>
Date:   Fri Sep 12 17:54:04 2025 +0200

    Update lintian overrides.
Created: 2025-09-12 Last update: 2025-11-06 19:31
news
[rss feed]
  • [2025-08-16] icingaweb2 2.12.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-10] Accepted icingaweb2 2.12.5-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-07-16] Accepted icingaweb2 2.12.5-1~exp1 (source) into experimental (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-05-20] icingaweb2 2.12.4-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-14] Accepted icingaweb2 2.12.4-2 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-03-31] icingaweb2 2.12.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-26] Accepted icingaweb2 2.12.4-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2024-11-19] icingaweb2 2.12.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-13] Accepted icingaweb2 2.12.2-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-11-21] icingaweb2 2.12.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-16] Accepted icingaweb2 2.12.1-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-10-06] icingaweb2 2.12.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-29] Accepted icingaweb2 2.12.0-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-09-22] Accepted icingaweb2 2.12.0-1~exp1 (source) into experimental (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-08-26] Accepted icingaweb2 2.11.4-2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Sebastiaan Couwenberg)
  • [2023-08-15] icingaweb2 2.11.4-3 MIGRATED to testing (Debian testing watch)
  • [2023-08-09] Accepted icingaweb2 2.11.4-3 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-02-02] icingaweb2 2.11.4-2 MIGRATED to testing (Debian testing watch)
  • [2023-01-28] Accepted icingaweb2 2.11.4-2 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-01-26] Accepted icingaweb2 2.11.4-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-12-20] icingaweb2 2.11.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-14] Accepted icingaweb2 2.11.3-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-12-10] icingaweb2 2.11.2-2 MIGRATED to testing (Debian testing watch)
  • [2022-12-05] Accepted icingaweb2 2.11.2-2 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-11-10] icingaweb2 2.11.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-05] Accepted icingaweb2 2.11.2-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-07-12] icingaweb2 2.11.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-12] icingaweb2 2.11.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-06] Accepted icingaweb2 2.11.1-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-07-05] Accepted icingaweb2 2.11.0-4 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.12.5-1
  • 6 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing