Icinga / Icinga
31 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-24413 | Icinga has insecure permission of %ProgramData%\icinga2\var on Windows | MEDIUM | 6.8 | Jan 29, 2026 |
| CVE-2025-61909 | Icinga 2 signals sent as root to processes based on PID file written by the Icinga 2 daemon user | MEDIUM | 4.0 | Oct 16, 2025 |
| CVE-2025-61908 | Icinga 2 Denial of Service (DoS) By Dereferencing Invalid Reference | HIGH | 7.1 | Oct 16, 2025 |
| CVE-2025-61907 | Icinga 2 API users could access restricted values in filter expressions | HIGH | 7.1 | Oct 16, 2025 |
| CVE-2025-48057 | Icinga 2 certificate renewal might incorrectly renew an invalid certificate | CRITICAL | 9.3 | May 27, 2025 |
| CVE-2024-49369 | Icinga 2 has a TLS Certificate Validation Bypass for JSON-RPC and HTTP API Connections | CRITICAL | 9.8 | Nov 12, 2024 |
| CVE-2024-24820 | Icinga Director configuration is susceptible to Cross-Site Request Forgery | HIGH | 8.3 | Feb 9, 2024 |
| CVE-2021-37698 | Missing TLS service certificate validation in GelfWriter, ElasticsearchWriter, InfluxdbWriter and Influxdb2Writer | HIGH | 7.5 | Aug 19, 2021 |
| CVE-2021-32743 | Passwords used to access external services inadvertently exposed through API | HIGH | 8.8 | Jul 15, 2021 |
| CVE-2021-32739 | Results of queries for ApiListener objects include the ticket salt which allows in turn to steal (more privileged) identities | HIGH | 8.8 | Jul 15, 2021 |
| CVE-2021-32747 | Custom variable protection and blacklists can be circumvented | MEDIUM | 6.5 | Jul 12, 2021 |
| CVE-2021-32746 | Possible path traversal by use of the `doc` module | MEDIUM | 5.3 | Jul 12, 2021 |
| CVE-2020-29663 | Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue… | CRITICAL | 9.1 | Dec 15, 2020 |
| CVE-2020-14004 | An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cm… | HIGH | 7.8 | Jun 12, 2020 |
| CVE-2018-6535 | An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker. | HIGH | 8.1 | Feb 27, 2018 |
| CVE-2018-6534 | An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause t… | MEDIUM | 6.5 | Feb 27, 2018 |
| CVE-2018-6533 | An issue was discovered in Icinga 2.x through 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run… | HIGH | 7.8 | Feb 27, 2018 |
| CVE-2018-6532 | An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot o… | HIGH | 7.5 | Feb 27, 2018 |
| CVE-2018-6536 | An issue was discovered in Icinga 2.x through 2.8.1. The daemon creates an icinga2.pid file after dropping privileges to a non-root account, which might allow… | MEDIUM | 5.5 | Feb 2, 2018 |
| CVE-2017-16933 | etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileg… | HIGH | 7.0 | Nov 24, 2017 |
| CVE-2017-16882 | Icinga Core through 1.14.0 initially executes bin/icinga as root but supports configuration options in which this file is owned by a non-root account (and simi… | HIGH | 7.8 | Nov 18, 2017 |
| CVE-2015-8010 | Cross-site scripting (XSS) vulnerability in the Classic-UI with the CSV export link and pagination feature in Icinga before 1.14 allows remote attackers to inj… | MEDIUM | 6.1 | Mar 27, 2017 |
| CVE-2014-2386 | Multiple off-by-one errors in Icinga, possibly 1.10.2 and earlier, allow remote attackers to cause a denial of service (crash) via unspecified vectors to the (… | MEDIUM | 5.0 | Mar 25, 2014 |
| CVE-2014-1878 | nagios: possible buffer overflows in cmd.cgi | MEDIUM | 5.0 | Feb 28, 2014 |
| CVE-2013-7108 | nagios: denial of service due to off-by-one flaw in process_cgivars() | MEDIUM | 5.5 | Jan 14, 2014 |
Showing 1 to 25 of 31 CVEs