Impact
The vulnerability allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user.
Patches
This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2.
Workarounds
If you have Icinga Web 2.12.2, enable CSP in the application settings.
Impact
The vulnerability allows an attacker to craft a URL that, once visited by any user, allows to embed arbitrary Javascript into Icinga Web and to act on behalf of that user.
Patches
This issue has been resolved in versions 2.11.5 and 2.12.3 of Icinga Web 2.
Workarounds
If you have Icinga Web 2.12.2, enable CSP in the application settings.