PT-2021-6701 · Icinga+1 · Icinga+1
Julianbrost
·
Published
2021-07-15
·
Updated
2024-11-16
·
CVE-2021-32739
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Icinga versions 2.4.0 through 2.12.4
Description
The issue concerns a monitoring system that checks network resource availability and generates performance data. It may allow privilege escalation for authenticated API users. With a read-only user's credentials, an attacker can view most attributes of config objects, including the
ticket salt of ApiListener. This information is sufficient to compute a ticket for every possible common name, which, along with the master node's certificate and a self-signed certificate, can be used to request a desired certificate from the system. This certificate may then be used to steal an endpoint or API user's identity.Recommendations
For versions 2.4.0 through 2.12.4, update to version 2.12.5 or 2.11.10 to resolve the issue.
As a temporary workaround, consider specifying queryable types explicitly or filter out ApiListener objects to minimize the risk of exploitation.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Icinga
Suse