GHSA-w9pg-7c3h-fc8j
GitHub Security Advisory
ipl/web's `ipl\Web\Common\CsrfCounterMeasure` is susceptible to CSRF
✓ GitHub Reviewed
LOW
Has CVE
Advisory Details
### Impact
Some of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF)
Affected products:
* Icinga Web (>=2.12.0)
* Icinga DB Web (>=1.0.0)
* Icinga Notifications Web (>=0.1.0)
* Icinga Web JIRA Integration (>=1.3.0)
All affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded.
### Patches
Version 0.10.1 will include a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.
Affected Packages
Packagist
ipl/web
Affected versions:
0
(fixed in 0.10.1)
Related CVEs
Key Information
2.5
/10
Dataset
Last updated: June 28, 2025 6:27 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.