Improper Certificate Validation in Icinga - CVE-2020-29663
Published: December 15, 2020 / Updated: June 29, 2026
Vulnerability details
The vulnerability allows a remote user to bypass certificate revocation checks.
The vulnerability exists due to improper certificate validation in the ApiListener certificate renewal logic when processing certificate renewal requests. A remote user can request automatic renewal of a revoked certificate to bypass certificate revocation checks.
Only setups using external certificate signing are affected, and exploitation requires that a CRL is configured and that the revoked certificate is eligible for automatic renewal because it was issued before 2017 or expires in less than 30 days.
Affected software
Gentoo Linux
net-analyzer/icinga2
How to mitigate CVE-2020-29663
net-analyzer/icinga2 - update to 2.14.3