Improper Certificate Validation in Icinga - CVE-2021-37698
Published: August 19, 2021 / Updated: June 29, 2026
Vulnerability details
The vulnerability allows a remote attacker to intercept sensitive information.
The vulnerability exists due to improper certificate validation in ElasticsearchWriter, GelfWriter, InfluxdbWriter, and Influxdb2Writer when establishing TLS connections to configured TSDB servers. A remote attacker can present a spoofed certificate to intercept sensitive information.
Exploitation requires a spoofable network infrastructure between the affected instance and the target TSDB service.
Affected software
Gentoo Linux
net-analyzer/icinga2
How to mitigate CVE-2021-37698
net-analyzer/icinga2 - update to 2.14.3