CVE-2020-29663: Critical severity icinga icinga web 2 vulnerability
Published Dec 15, 2020
·Updated
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
Affected Software
2 affected components
Icinga Icinga>=2.8.0<=2.11.7
Icinga Icinga=2.12.2
Remediation
Patch Available
Event History
Dec 15, 2020
CVE Published
via MITRE·10:15 PM
Data Sourced
via MITRE·10:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-29663?
The severity of CVE-2020-29663 is critical with a severity value of 9.1.
2
What is the affected software for CVE-2020-29663?
The affected software for CVE-2020-29663 is Icinga 2 versions 2.8.0 through 2.11.7 and 2.12.2.
3
How can I fix CVE-2020-29663?
To fix CVE-2020-29663, update to Icinga 2 versions 2.11.8 or 2.12.3.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2020-29663?
The Common Weakness Enumeration (CWE) ID for CVE-2020-29663 is CWE-295.
5
Where can I find more information about CVE-2020-29663?
You can find more information about CVE-2020-29663 on the Icinga GitHub repository and the Icinga security advisories page.