VDB
CVE-2012-3441
CVE-2012-3441
PUBLISHED
CVSS 7.5 HIGH
The database creation script (module/idoutils/db/scripts/create_mysqldb.sh) in Icinga 1.7.1 grants access to all databases to the icinga user, which allows icinga users to access other databases via unspecified vectors.
EPSS 0.59% · 69.6th percentile
Risk Scores
CVSS 2.0
7.5
EPSS Score
0.59%
69.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| icinga | icinga | 1.7.1 |
| n/a | n/a | n/a |
Timeline
- Aug 25, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
- Jul 17, 2023 EPSS Score
References
- [oss-security] 20120730 Re: CVE Request: icinga sample db creation scripts mailing-list
- https://git.icinga.org/?p=icinga-core.git%3Ba=commitdiff%3Bh=dcd45fb6931c4abf710829bee21af09f842bc281 url
- https://git.icinga.org/?p=icinga-core.git%3Ba=commitdiff%3Bh=712813d3118a5b9e5a496179cab81dbe91f69d63 url
- [oss-security] 20120730 CVE Request: icinga sample db creation scripts mailing-list
- icinga-database-sec-bypass(78874) vdb
- https://git.icinga.org/?p=icinga-doc.git%3Ba=commitdiff%3Bh=619a08ca1178144b8a3a5caafff32a2d3918edab url
- openSUSE-SU-2012:0968 vendor-advisory
- https://bugzilla.novell.com/show_bug.cgi?id=767319 url
- https://nvd.nist.gov/vuln/detail/CVE-2012-3441 advisory
- https://git.icinga.org/?p=icinga-core.git;a=commitdiff;h=712813d3118a5b9e5a496179cab81dbe91f69d63 url
- https://git.icinga.org/?p=icinga-core.git;a=commitdiff;h=dcd45fb6931c4abf710829bee21af09f842bc281 url
- https://git.icinga.org/?p=icinga-doc.git;a=commitdiff;h=619a08ca1178144b8a3a5caafff32a2d3918edab url