File _patchinfo of Package patchinfo.17435
<patchinfo incident="17435">
<issue tracker="bnc" id="1196913">VUL-0: CVE-2022-24714: icingaweb2: Unwanted disclosure of hosts and related data, linked to decommissioned services</issue>
<issue tracker="bnc" id="1196911">VUL-0: CVE-2022-24715: icingaweb2: SSH resources allow arbitrary code execution for authenticated users</issue>
<issue tracker="cve" id="2022-24714"/>
<issue tracker="cve" id="2022-24715"/>
<packager>ecsos</packager>
<rating>important</rating>
<category>security</category>
<summary>Security update for icingaweb2</summary>
<description>This update for icingaweb2 fixes the following issues:
icingaweb2 was updated to 2.8.6
This is a security release.
* Security Fixes
- CVE-2022-24715: SSH resources allow arbitrary code execution for authenticated users (GHSA-v9mv-h52f-7g63 boo#1196911)
- CVE-2022-24714: Unwanted disclosure of hosts and related data, linked to decommissioned services (GHSA-qcmg-vr56-x9wf boo#1196913)
</description>
</patchinfo>