Debian Package Tracker
Register | Log in
Subscribe

icingaweb2

simple and responsive web interface for Icinga

Choose email to subscribe with

general
  • source: icingaweb2 (main)
  • version: 2.12.6-1
  • maintainer: Debian Nagios Maintainer Group (archive) (DMD)
  • uploaders: Markus Frosch [DMD] – Bas Couwenberg [DMD]
  • arch: all
  • std-ver: 4.7.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.8.2-2
  • oldstable: 2.11.4-2+deb12u1
  • stable: 2.12.4-2
  • testing: 2.12.6-1
  • unstable: 2.12.6-1
versioned links
  • 2.8.2-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.11.4-2+deb12u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.4-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.12.6-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • icingacli
  • icingaweb2
  • icingaweb2-common
  • icingaweb2-module-doc
  • icingaweb2-module-monitoring
  • php-icinga
action needed
4 security issues in bookworm high

There are 4 open security issues in bookworm.

4 important issues:
  • CVE-2025-27404: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.
  • CVE-2025-27405: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.
  • CVE-2025-27609: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a request that, once transmitted to a victim's Icinga Web, allows to embed arbitrary Javascript into it and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings. Any modern browser with a working CORS implementation also sufficiently guards against the vulnerability.
  • CVE-2025-30164: Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 vulnerability allows an attacker to craft a URL that, once visited by an authenticated user (or one that is able to authenticate), allows to manipulate the backend to redirect the user to any location. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. No known workarounds are available.
Created: 2025-03-27 Last update: 2025-11-25 06:16
news
[rss feed]
  • [2025-11-25] icingaweb2 2.12.6-1 MIGRATED to testing (Debian testing watch)
  • [2025-11-19] Accepted icingaweb2 2.12.6-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-08-16] icingaweb2 2.12.5-1 MIGRATED to testing (Debian testing watch)
  • [2025-08-10] Accepted icingaweb2 2.12.5-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-07-16] Accepted icingaweb2 2.12.5-1~exp1 (source) into experimental (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-05-20] icingaweb2 2.12.4-2 MIGRATED to testing (Debian testing watch)
  • [2025-05-14] Accepted icingaweb2 2.12.4-2 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2025-03-31] icingaweb2 2.12.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-03-26] Accepted icingaweb2 2.12.4-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2024-11-19] icingaweb2 2.12.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-13] Accepted icingaweb2 2.12.2-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-11-21] icingaweb2 2.12.1-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-16] Accepted icingaweb2 2.12.1-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-10-06] icingaweb2 2.12.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-29] Accepted icingaweb2 2.12.0-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-09-22] Accepted icingaweb2 2.12.0-1~exp1 (source) into experimental (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-08-26] Accepted icingaweb2 2.11.4-2+deb12u1 (source) into proposed-updates (Debian FTP Masters) (signed by: Sebastiaan Couwenberg)
  • [2023-08-15] icingaweb2 2.11.4-3 MIGRATED to testing (Debian testing watch)
  • [2023-08-09] Accepted icingaweb2 2.11.4-3 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-02-02] icingaweb2 2.11.4-2 MIGRATED to testing (Debian testing watch)
  • [2023-01-28] Accepted icingaweb2 2.11.4-2 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2023-01-26] Accepted icingaweb2 2.11.4-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-12-20] icingaweb2 2.11.3-1 MIGRATED to testing (Debian testing watch)
  • [2022-12-14] Accepted icingaweb2 2.11.3-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-12-10] icingaweb2 2.11.2-2 MIGRATED to testing (Debian testing watch)
  • [2022-12-05] Accepted icingaweb2 2.11.2-2 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-11-10] icingaweb2 2.11.2-1 MIGRATED to testing (Debian testing watch)
  • [2022-11-05] Accepted icingaweb2 2.11.2-1 (source) into unstable (Bas Couwenberg) (signed by: Sebastiaan Couwenberg)
  • [2022-07-12] icingaweb2 2.11.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-12] icingaweb2 2.11.1-1 MIGRATED to testing (Debian testing watch)
  • 1
  • 2
bugs [bug history graph]
  • all: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.12.6-1
  • 6 bugs

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing