Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. Installations of Icinga 2 with the IDO writer enabled are affected. If you use service custom variables in role restrictions, and you regularly decommission service objects, users with said roles may still have access to a collection of content. Note that this only applies if a role has implicitly permitted access to hosts, due to permitted access to at least one of their services. If access to a host is permitted by other means, no sensible information has been disclosed to unauthorized users. This issue has been resolved in versions 2.8.6, 2.9.6 and 2.10 of Icinga Web 2.
Conclusion & alert: CVE-2022-24714 is rated Moderate Risk (40/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.32%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-08-06 | 0.49% | 0.32% | -0.17% |
| 2 | 2025-08-05 | 0.19% | 0.49% | +0.30% |
| 3 | 2025-03-30 | — | 0.19% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 5.3 | 3.1 | MEDIUM |
|
3.9 | 1.4 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2022-24714 not yet assigned priority: Debian including 1 source packages (icingaweb2), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 4, open 1. | https://security-tracker.debian.org/tracker/CVE-2022-24714 |
gentoo
|
high | CVE-2022-24714: 1 GLSA(s) (202208-05), 1 atom(s) (www-apps/icingaweb2); latest impact high. | https://bugs.gentoo.org/buglist.cgi?quicksearch=CVE-2022-24714 |
ubuntu
|
medium | CVE-2022-24714 medium priority: Ubuntu including 1 source packages (icingaweb2), 14 status rows across 14 suites (bionic, focal, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): not-affected 7, ignored 3, needed 3, released 1. | https://ubuntu.com/security/CVE-2022-24714 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| icinga | icinga_web_2 | < 2.8.6 | cpe:2.3:a:icinga:icinga_web_2:*:*:*:*:*:*:*:* |
| icinga | icinga_web_2 | >= 2.9.0, < 2.9.6 | cpe:2.3:a:icinga:icinga_web_2:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/Icinga/icingaweb2/commit/6e989d05a1568a6733a3d912001251acc51d9293 | Patch Third Party Advisory |
| https://github.com/Icinga/icingaweb2/security/advisories/GHSA-qcmg-vr56-x9wf | Third Party Advisory |
| https://security.gentoo.org/glsa/202208-05 | Third Party Advisory |