Skip to content

Missing TLS server certificate validation in ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer

Low
N-o-X published GHSA-cxfm-8j5v-5qr2 Aug 19, 2021

Package

No package listed

Affected versions

v2.5.0 through v2.13.0

Patched versions

v2.13.1, v2.12.6 and v2.11.11

Description

Impact

Despite a CA is specified, none of ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer verify the server's certificate.

Patches

Icinga 2 instances which connect to any of the mentioned TSDBs using TLS over a spoofable infrastructure should immediately upgrade and change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB.

Workarounds

None.

References

Blogpost: https://icinga.com/blog/2021/08/19/icinga-2-13-1-security-release/

For more information

If you have any questions or comments about this advisory:

Severity

Low

CVE ID

CVE-2021-37698

Weaknesses