Vulnerability Description
Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server's certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mentioned time series databases (TSDBs) using TLS over a spoofable infrastructure should immediately upgrade to version 2.13.1, 2.12.6, or 2.11.11 to patch the issue. Such instances should also change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB. There are no workarounds aside from upgrading.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Icinga | Icinga | >= 2.5.0, < 2.11.10 |
| Debian | Debian Linux | 9.0 |
Related Weaknesses (CWE)
References
- https://github.com/Icinga/icinga2/releases/tag/v2.11.11Release NotesThird Party Advisory
- https://github.com/Icinga/icinga2/releases/tag/v2.12.6Release NotesThird Party Advisory
- https://github.com/Icinga/icinga2/releases/tag/v2.13.1Release NotesThird Party Advisory
- https://github.com/Icinga/icinga2/security/advisories/GHSA-cxfm-8j5v-5qr2Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00010.htmlMailing ListThird Party Advisory
- https://github.com/Icinga/icinga2/releases/tag/v2.11.11Release NotesThird Party Advisory
- https://github.com/Icinga/icinga2/releases/tag/v2.12.6Release NotesThird Party Advisory
- https://github.com/Icinga/icinga2/releases/tag/v2.13.1Release NotesThird Party Advisory
- https://github.com/Icinga/icinga2/security/advisories/GHSA-cxfm-8j5v-5qr2Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2021/11/msg00010.htmlMailing ListThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2024/11/msg00010.html
FAQ
What is CVE-2021-37698?
CVE-2021-37698 is a vulnerability with a CVSS score of 7.5 (HIGH). Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, Elasticsear...
How severe is CVE-2021-37698?
CVE-2021-37698 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-37698?
Check the references section above for vendor advisories and patch information. Affected products include: Icinga Icinga, Debian Debian Linux.