Source: icingaweb2-module-reporting
Version: 1.0.2-2
Severity: important
Tags: security upstream
X-Debbugs-Cc: car...@debian.org, Debian Security Team <t...@security.debian.org>

Hi,

The following vulnerability was published for icingaweb2-module-reporting.

CVE-2025-27406[0]:
| Icinga Reporting is the central component for reporting related
| functionality in the monitoring web frontend and framework Icinga
| Web 2. A vulnerability present in versions 0.10.0 through 1.0.2
| allows to set up a template that allows to embed arbitrary
| Javascript. This enables the attacker to act on behalf of the user,
| if the template is being previewed; and act on behalf of the
| headless browser, if a report using the template is printed to PDF.
| This issue has been resolved in version 1.0.3 of Icinga Reporting.
| As a workaround, review all templates and remove suspicious
| settings.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-27406
    https://www.cve.org/CVERecord?id=CVE-2025-27406
[1] 
https://github.com/Icinga/icingaweb2-module-reporting/security/advisories/GHSA-7qvq-54vm-r7hx

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to