SUSE-SU-2022:3725-1
Dashboard / Vulnerabilities / SUSE-SU-2022:3725-1
SUSE-SU-2022:3725-1
Summary: Security update for icinga2
Details: This update for icinga2 fixes the following issues: - CVE-2020-14004: prepare-dirs script allows for symlink attack in the icinga user context. (bsc#1172171) - CVE-2020-29663: ignoring CRL, where revoked certificates due for renewal will automatically be renewed. (bsc#281137) - CVE-2021-37698: Missing TLS server certificate validation in ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer. (bsc#281137)
References: https://www.suse.com/support/update/announcement/2022/suse-su-20223725-1/, https://bugzilla.suse.com/1172171, https://bugzilla.suse.com/1180147, https://bugzilla.suse.com/1189653, https://www.suse.com/security/cve/CVE-2020-14004, https://www.suse.com/security/cve/CVE-2020-29663, https://www.suse.com/security/cve/CVE-2021-37698
Affected packages
Package
Name: icinga2
Purl: pkg:rpm/suse/icinga2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012
Affected ranges
Type: ECOSYSTEM
Events:
