logo

Database

Reflected cross-site scripting (XSS) In ipl/web

Description

ipl/web is vulnerable to reflected XSS by malformed search requests

Impact

The vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no immediate chance to notice any wrongdoing.

Patches

Version 0.13.1 includes a fix for this. It will be published as part of icinga-php-library version 0.19.2.

Workarounds

Enable the Content-Security-Policy (CSP) in the general configuration of Icinga Web available since version 2.12.0.

References

None

Mitigation

Update Impact

Minimal update. May introduce new vulnerabilities or breaking changes.

Ecosystem
Component
Affected version
Patched versions