CVE-2020-29663Improper Certificate Validation in Icinga

Severity
9.1CRITICALNVD
EPSS
0.6%
top 31.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15

Description

Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NExploitability: 3.9 | Impact: 5.2

Affected Packages2 packages

Debianicinga/icinga2< 2.12.3-1+3
NVDicinga/icinga2.8.02.11.7+1

Patches

🔴Vulnerability Details

2
CVEList
CVE-2020-29663: Icinga 2 v22020-12-15
OSV
CVE-2020-29663: Icinga 2 v22020-12-15

📋Vendor Advisories

1
Debian
CVE-2020-29663: icinga2 - Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certifica...2020
CVE-2020-29663 — Improper Certificate Validation | cvebase