📦 Icinga

by Icinga

🔍 What is Icinga?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-48057

CRITICAL CVSS 9.8 May 27, 2025

A certificate validation vulnerability in Icinga 2 allows attackers to obtain valid certificates by tricking the system into treating malicious certificate requests as renewals. This enables impersona...

CVE-2024-49369

CRITICAL CVSS 9.8 Nov 12, 2024

CVE-2024-49369 is a critical TLS certificate validation flaw in Icinga 2 that allows attackers to impersonate trusted cluster nodes and API users using TLS client certificates. This enables unauthoriz...

CVE-2020-29663

CRITICAL CVSS 9.1 Dec 15, 2020

This vulnerability in Icinga 2 allows revoked certificates to be automatically renewed despite being on a Certificate Revocation List (CRL), bypassing certificate revocation checks. This affects Icing...

CVE-2024-24820

HIGH CVSS 8.3 Feb 9, 2024

CVE-2024-24820 is a Cross-Site Request Forgery (CSRF) vulnerability in Icinga Director that allows attackers to perform unauthorized configuration changes in monitoring environments. All Icinga Direct...

CVE-2021-32743

HIGH CVSS 8.8 Jul 15, 2021

Icinga 2 monitoring system exposes sensitive credentials (database, Redis, Elasticsearch passwords) through its API to authenticated users with read permissions. This allows attackers who obtain API a...

CVE-2026-24413

MEDIUM CVSS 5.5 Jan 29, 2026

The Icinga 2 MSI installer on Windows sets overly permissive folder permissions, allowing all local users to read sensitive files including private keys and configuration data. This affects all Window...

CVE-2025-61909

MEDIUM CVSS 4.4 Oct 16, 2025

This vulnerability allows the Icinga daemon user to send signals to arbitrary processes by exploiting a race condition in the safe-reload script and logrotate configuration. The issue occurs because t...

CVE-2025-61907

MEDIUM CVSS 6.5 Oct 16, 2025

This vulnerability allows authenticated API users in Icinga 2 to bypass permission restrictions and access sensitive information they shouldn't have access to. Attackers can exploit filter expressions...

CVE-2025-61908

MEDIUM CVSS 6.5 Oct 16, 2025

This vulnerability in Icinga 2 allows any authenticated API user to crash the monitoring daemon by creating invalid references (like null references) in filter expressions. It affects Icinga 2 version...