PT-2021-21818 · Icinga+1 · Icinga+1

N-O-X

·

Published

2021-08-19

·

Updated

2024-11-16

·

CVE-2021-37698

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Icinga versions 2.5.0 through 2.13.0
Description Icinga is a monitoring system that checks the availability of network resources, notifies users of outages, and generates performance data for reporting. The issue arises in the ElasticsearchWriter, GelfWriter, InfluxdbWriter, and Influxdb2Writer components, which do not verify the server's certificate despite a certificate authority being specified. This affects Icinga 2 instances that connect to time series databases (TSDBs) using TLS over a spoofable infrastructure.
Recommendations For Icinga versions 2.5.0 through 2.13.0, upgrade to version 2.13.1, 2.12.6, or 2.11.11 to patch the issue. Change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB. Note that there are no workarounds aside from upgrading.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2021-37698
DLA-2816-1
DLA-3953-1
GHSA-CXFM-8J5V-5QR2
OPENSUSE-SU-2024:10856-1
SUSE-SU-2022:3725-1

Affected Products

Icinga
Suse