Improper Certificate Validation in Icinga - CVE-2020-29663

 

Improper Certificate Validation in Icinga - CVE-2020-29663

Published: December 15, 2020 / Updated: June 29, 2026


Vulnerability identifier: #VU135835
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-29663
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass certificate revocation checks.

The vulnerability exists due to improper certificate validation in the ApiListener certificate renewal logic when processing certificate renewal requests. A remote user can request automatic renewal of a revoked certificate to bypass certificate revocation checks.

Only setups using external certificate signing are affected, and exploitation requires that a CRL is configured and that the revoked certificate is eligible for automatic renewal because it was issued before 2017 or expires in less than 30 days.


Affected software

Icinga
Gentoo Linux
net-analyzer/icinga2

How to mitigate CVE-2020-29663

Install security update from vendor's website.

Icinga - addressed in versions 2.11.8, 2.12.3
net-analyzer/icinga2 - update to 2.14.3

External References

Related Security Bulletins