Improper access control in Icinga - CVE-2021-32743
Published: July 15, 2021 / Updated: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to improper access control in the Icinga API object query handling for IdoMysqlConnection, IdoPgsqlConnection, IcingaDB, and ElasticsearchWriter objects when processing read requests for corresponding object types. A remote user can query affected objects to disclose sensitive information.
Exposed credentials may allow access to external database, Redis, or Elasticsearch services with the permissions assigned to those credentials.
Affected software
Gentoo Linux
net-analyzer/icinga2
How to mitigate CVE-2021-32743
net-analyzer/icinga2 - update to 2.14.3