Loading HuntDB...

GHSA-w9pg-7c3h-fc8j

GitHub Security Advisory

ipl/web's `ipl\Web\Common\CsrfCounterMeasure` is susceptible to CSRF

✓ GitHub Reviewed LOW Has CVE

Advisory Details

### Impact
Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF)

Affected products:

* Icinga Web (>=2.12.0)
* Icinga DB Web (>=1.0.0)
* Icinga Notifications Web (>=0.1.0)
* Icinga Web JIRA Integration (>=1.3.0)

All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded.

### Patches
Version 0.10.1 will include a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.

Affected Packages

Packagist ipl/web
Affected versions: 0 (fixed in 0.10.1)

Related CVEs

Key Information

GHSA ID
GHSA-w9pg-7c3h-fc8j
Published
August 5, 2024 2:39 PM
Last Modified
August 6, 2024 2:41 PM
CVSS Score
2.5 /10
Primary Ecosystem
Packagist
Primary Package
ipl/web
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 28, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.