Critical Icinga 2 Vulnerability Allows Attackers to Obtain Valid Certificates
ID: c76b5024-d830-50f5-9ade-42774da88152
STIX ID: report--c76b5024-d830-50f5-9ade-42774da88152
Feed Name: Cyber Press
Security researchers disclosed a critical vulnerability in Icinga 2 affecting installations that use OpenSSL versions prior to 1.1.0 (notably RHEL 7 and derivatives). The flaw in the VerifyCertificate() function can be abused to have the Icinga CA issue legitimate certificates for attacker-controlled requests, enabling impersonation of trusted nodes if an attacker can establish a direct TLS connection to a signing master. Patches (Icinga 2.14.6, 2.13.12, 2.12.12) and temporary mitigations (restricting master access or disabling certificate signing by renaming the CA directory) have been released, and updated binaries and source are available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
