{"id":"CVE-2024-41811","aliases":["GHSA-w9pg-7c3h-fc8j"],"url":"https://o3.security/vulnerability/CVE-2024-41811","summary":"ipl/web susceptible to Cross-Site Request Forgery (CSRF)","details":"### Impact\nSome of the recent development by Icinga is, under certain circumstances, susceptible to cross site request forgery. (CSRF)\n\nAffected products:\n\n* Icinga Web (>=2.12.0)\n* Icinga DB Web (>=1.0.0)\n* Icinga Notifications Web (>=0.1.0)\n* Icinga Web JIRA Integration (>=1.3.0)\n\nAll affected products, in any version, will be unaffected by this once `icinga-php-library` is upgraded.\n\n### Patches\nVersion 0.10.1 will include a fix for this. It will be published as part of the `icinga-php-library` v0.14.1 release.\n","published":"2024-08-05T20:17:30.849Z","modified":"2026-08-12T03:51:36.067545660Z","cvss":{"score":3.9,"severity":"LOW","vector":"CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"ipl/web","fixedVersion":"0.10.1"}],"fix":{"url":"https://github.com/Icinga/ipl-web/commit/492336fdb57a5bb0881ed642ab36f5841337571e","label":"Icinga/ipl-web@492336f"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/41xxx/CVE-2024-41811.json"},{"type":"ADVISORY","url":"https://github.com/Icinga/ipl-web/security/advisories/GHSA-w9pg-7c3h-fc8j"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-41811"},{"type":"FIX","url":"https://github.com/Icinga/ipl-web/commit/492336fdb57a5bb0881ed642ab36f5841337571e"},{"type":"PACKAGE","url":"https://github.com/Icinga/ipl-web"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:36.067545660Z"}}