Improper Certificate Validation in Icinga - CVE-2020-29663
Published: December 15, 2020 / Updated: June 29, 2026
Icinga
Detailed vulnerability description
The vulnerability allows a remote user to bypass certificate revocation checks.
The vulnerability exists due to improper certificate validation in the ApiListener certificate renewal logic when processing certificate renewal requests. A remote user can request automatic renewal of a revoked certificate to bypass certificate revocation checks.
Only setups using external certificate signing are affected, and exploitation requires that a CRL is configured and that the revoked certificate is eligible for automatic renewal because it was issued before 2017 or expires in less than 30 days.