Update Info

openSUSE-2022-97


Security update for icingaweb2


Type: security
Severity: important
Issued: 2022-03-31
Description:
This update for icingaweb2 fixes the following issues:

icingaweb2 was updated to 2.8.6

This is a security release.

* Security Fixes

- CVE-2022-24715: SSH resources allow arbitrary code execution for authenticated users (GHSA-v9mv-h52f-7g63 boo#1196911)
- CVE-2022-24714: Unwanted disclosure of hosts and related data, linked to decommissioned services (GHSA-qcmg-vr56-x9wf boo#1196913)


              

Packages


  • icingaweb2-2.8.6-bp153.2.3.1