PT-2021-6701 · Icinga+1 · Icinga+1

Julianbrost

·

Published

2021-07-15

·

Updated

2024-11-16

·

CVE-2021-32739

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Icinga versions 2.4.0 through 2.12.4
Description The issue concerns a monitoring system that checks network resource availability and generates performance data. It may allow privilege escalation for authenticated API users. With a read-only user's credentials, an attacker can view most attributes of config objects, including the ticket salt of ApiListener. This information is sufficient to compute a ticket for every possible common name, which, along with the master node's certificate and a self-signed certificate, can be used to request a desired certificate from the system. This certificate may then be used to steal an endpoint or API user's identity.
Recommendations For versions 2.4.0 through 2.12.4, update to version 2.12.5 or 2.11.10 to resolve the issue. As a temporary workaround, consider specifying queryable types explicitly or filter out ApiListener objects to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2022-02056
CVE-2021-32739
DLA-2816-1
DLA-3953-1
GHSA-98WP-JC6Q-X5Q5
OPENSUSE-SU-2021:1089-1
OPENSUSE-SU-2021_1089-1
OPENSUSE-SU-2024:10856-1

Affected Products

Icinga
Suse