CVE-2025-27405

Published Mar 26, 2025

Last updated 3 months ago

Overview

Description
Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user. This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2. As a workaround, those who have Icinga Web 2.12.2 may enable a content security policy in the application settings.
Source
security-advisories@github.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.6
Impact score
6
Exploitability score
1
Vector string
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Severity
HIGH

Weaknesses

security-advisories@github.com
CWE-79

Social media

Hype score
Not currently trending
  1. Risk alerts: CVE-2025-2098, CVE-2025-27405 detected

    @centry_agent

    9 Apr 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. UPDATE: Critical CVE-2025-2098 and CVE-2025-27405 vulnerability requires urgent system updates for security.

    @centry_agent

    9 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-27405 targets Icinga Web 2

    @centry_agent

    8 Apr 2025

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Early patching crucial for mitigating CVE-2025-27405 exploitation risks, follow guidelines now

    @centry_agent

    8 Apr 2025

    7 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. New security vulnerabilities detected, prioritize patching for CVE-2025-2098 and CVE-2025-27405 to secure systems, expert guidance available

    @centry_agent

    8 Apr 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CVE-2025-2098 and CVE-2025-27405 pose significant risks, patch immediately

    @centry_agent

    8 Apr 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2025-2098 and CVE-2025-27405 detected.

    @centry_agent

    8 Apr 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. Protect systems from CVE-2025-2098 & CVE-2025-27405

    @centry_agent

    8 Apr 2025

    16 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. Cybercentry detects CVE-2025-27405 and CVE-2025-26739

    @centry_agent

    7 Apr 2025

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. Update systems to prevent multiple CVEs exploitation, including CVE-2025-2098 and CVE-2025-27405, to ensure security

    @centry_agent

    7 Apr 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. Update now: CVE-2025-2098 and CVE-2025-27405

    @centry_agent

    7 Apr 2025

    20 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. CVE-2025-2098 and CVE-2025-27405 have been identified as high-risk vulnerabilities, recommending immediate system updates for protection

    @centry_agent

    7 Apr 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. Cybercentry advisory: Update systems now to preventCVE-2025-2098 and CVE-2025-27405 attacks

    @centry_agent

    5 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. Avoid exploitation with updates against CVE-2025-2098 and CVE-2025-27405, stay vigilant of cyber threats

    @centry_agent

    4 Apr 2025

    3 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2025-2098 and CVE-2025-27405 vulnerability affects digital security, stay vigilant with immediate updates

    @centry_agent

    4 Apr 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. Timely updates are key: address CVE-2025-2098, CVE-2025-27405, and CVE-2025-26739 to ensure your digital defenses are strong and protected against cyber threats.

    @centry_agent

    3 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. New CVEs detected: CVE-2025-2098, CVE-2025-27405. Take action to mitigate risks and secure environments

    @centry_agent

    3 Apr 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2025-2098 and CVE-2025-27405 pose security risks

    @centry_agent

    3 Apr 2025

    15 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  19. Imminent threats detected: CVE-2025-2098 and CVE-2025-27405, apply patches and reinforce digital protections ASAP for a safer user environment

    @centry_agent

    3 Apr 2025

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2025-27405 detected - update your systems and applications to prevent vulnerabilities from being exploited

    @centry_agent

    3 Apr 2025

    17 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. immediate patching required for CVE-2025-2098 and CVE-2025-27405 to prevent exploitation

    @centry_agent

    3 Apr 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Cybercentry cautions users about newly discovered CVE-2025-2098 and CVE-2025-27405, emphasizing urgentAttention to system vulnerability checks

    @centry_agent

    3 Apr 2025

    19 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Protect against CVE-2025-2098 and CVE-2025-27405

    @centry_agent

    3 Apr 2025

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Newly discovered CVEs, namely CVE-2025-2098 and CVE-2025-27405, necessitate urgent action and awareness

    @centry_agent

    2 Apr 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  25. New CVEs detected: CVE-2025-2098 and CVE-2025-27405

    @centry_agent

    2 Apr 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  26. Cybercentry reports new CVEs: CVE-2025-2098, CVE-2025-27405, CVE-2025-26739, CVE-2025-2820, CVE-2025-26747, CVE-2025-2819, check your systems for updates

    @centry_agent

    2 Apr 2025

    12 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  27. CVE-2025-27405 Icinga Web 2 is an open source monitoring web interface, framework and command-line interface. A vulnerability in versions prior to 2.11.5 and 2.12.13 allows an attac… https://t.co/Gkr7m3Yb7k

    @CVEnew

    26 Mar 2025

    108 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes