{"id":"CVE-2020-24368","details":"Icinga Icinga Web2 2.0.0 through 2.6.4, 2.7.4 and 2.8.2 has a Directory Traversal vulnerability which allows an attacker to access arbitrary files that are readable by the process running Icinga Web 2. This issue is fixed in Icinga Web 2 in v2.6.4, v2.7.4 and v2.8.2.","modified":"2026-07-08T05:55:55.270022692Z","published":"2020-08-19T15:15:12.620Z","related":["openSUSE-SU-2020:1674-1","openSUSE-SU-2024:10857-1"],"database_specific":{"unresolved_ranges":[{"source":"CPE_STRING","vendor_product":"debian:debian_linux","cpes":["cpe:2.3:o:debian:debian_linux:10:*:*:*:*:*:*:*","cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"9.0"},{"last_affected":"9.0"},{"introduced":"10"},{"last_affected":"10"}]}]},"references":[{"type":"ADVISORY","url":"http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00026.html"},{"type":"ADVISORY","url":"https://github.com/Icinga/icingaweb2/blob/master/CHANGELOG.md"},{"type":"ADVISORY","url":"https://icinga.com/2020/08/19/icinga-web-security-release-v2-6-4-v2-7-4-and-v2-8-2/"},{"type":"ADVISORY","url":"https://lists.debian.org/debian-lts-announce/2020/08/msg00040.html"},{"type":"ADVISORY","url":"https://security.gentoo.org/glsa/202208-05"},{"type":"ADVISORY","url":"https://www.debian.org/security/2020/dsa-4747"},{"type":"REPORT","url":"https://github.com/Icinga/icingaweb2/issues/4226"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/icinga/icingaweb2","events":[{"introduced":"ee1ee5af84d32c4493365959aa8a4322a34582e4"},{"fixed":"53714b7ea40ffd5a42b0b1d26339b5f3af38a908"},{"introduced":"861c5601b6e01402a932687d7b59a037c72a6804"},{"fixed":"3ebfb5c38330d22966d24d2ace57d7eb3fb2a6db"},{"introduced":"642ec11228c3be8d2abbdff6ef31da77e34f6c70"},{"fixed":"8a89839af94a247ee2149b2336c73b8251b477c0"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:icinga:icinga_web_2:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2.0.0"},{"fixed":"2.6.4"},{"introduced":"2.7.0"},{"fixed":"2.7.4"},{"introduced":"2.8.0"},{"fixed":"2.8.2"}]}}],"versions":["v2.6.3","v2.7.3","v2.8.1","v2.8.0","v2.7.2","v2.7.1","v2.7.0","v2.6.2","v2.6.1","v2.6.0","v2.5.3","v2.5.2","v2.5.1","v2.5.0","v2.4.0-2","v2.4.0","v2.3.4","v2.3.3","v2.3.2","v2.2.0","v2.1.2","v2.3.1","v2.3.0","v2.1.1","v2.1.0","v2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-24368.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}