{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3adegamisuopen-irs/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:degamisu:open-irs:*:*:*:*:*:*:*:*","cpe:2.3:a:nodejs:undici:*:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":7.6,"id":"CVE-2024-24757"},{"cvss":3.9,"id":"CVE-2024-24758"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Icinga Web"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","webserver"],"_cs_type":"advisory","_cs_vendors":["Icinga"],"content_html":"\u003cp\u003eIcinga has announced multiple security vulnerabilities (CVE-2024-24757 and CVE-2024-24758) affecting Icinga Web. These flaws allow a remote, unauthenticated attacker to impact the availability of the monitoring interface through Denial of Service (DoS) conditions or gain access to unauthorized information. The vulnerabilities stem from improper request handling within the application's logic. Defenders should prioritize patching Icinga Web instances to the latest vendor-provided version to mitigate the risk of service interruption and potential data exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of these vulnerabilities can lead to a complete loss of availability for the Icinga monitoring system, hindering operational visibility. Additionally, the disclosure of sensitive information can lead to further reconnaissance opportunities for an attacker. These vulnerabilities affect all deployments of Icinga Web where the vulnerable code paths are reachable by remote requests.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply vendor security patches for CVE-2024-24757 and CVE-2024-24758 immediately across all Icinga Web installations.\u003c/li\u003e\n\u003cli\u003eAudit web server access logs for anomalous request patterns targeting Icinga Web endpoints that result in repeated 5xx status codes, which may indicate attempted DoS exploitation.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-18T14:50:24Z","date_published":"2026-08-18T14:50:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-icinga-vulnerabilities/","summary":"Remote attackers can exploit multiple vulnerabilities in Icinga Web to conduct Denial of Service attacks or disclose sensitive information due to improper request handling.","title":"Multiple Vulnerabilities in Icinga Web","url":"https://feed.craftedsignal.io/briefs/2026-08-icinga-vulnerabilities/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:degamisu:open-Irs:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}