First published: Tue Dec 15 2020(Updated: )
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga | >=2.8.0<=2.11.7 | |
Icinga Icinga | =2.12.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-29663 is critical with a severity value of 9.1.
The affected software for CVE-2020-29663 is Icinga 2 versions 2.8.0 through 2.11.7 and 2.12.2.
To fix CVE-2020-29663, update to Icinga 2 versions 2.11.8 or 2.12.3.
The Common Weakness Enumeration (CWE) ID for CVE-2020-29663 is CWE-295.
You can find more information about CVE-2020-29663 on the Icinga GitHub repository and the Icinga security advisories page.