Icinga 2 Vulnerabilities Allow Unauthenticated Node Takeover
ID: 986c5732-de90-5367-87b5-1059bcd106a8
STIX ID: report--986c5732-de90-5367-87b5-1059bcd106a8
Feed Name: securityonline.info
Icinga 2 released fixes for three critical vulnerabilities (an unauthenticated certificate takeover allowing node/CA replacement, an unauthenticated stack overflow that can crash the service, and an authenticated DSL injection via the /v1/objects API) affecting releases prior to v2.16.2/v2.15.4/v2.14.9; administrators are advised to upgrade immediately, restrict TCP/5665 access, and remove objects/create rights from untrusted API users — no active exploitation has been confirmed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
