Action not permitted
Modal body text goes here.
Modal Title
Modal Body
CVE-2020-29663 (GCVE-0-2020-29663)
Vulnerability from cvelistv5
Published
2020-12-15 22:15
Modified
2024-08-04 16:55
Severity ?
VLAI Severity ?
EPSS score ?
CWE
- n/a
Summary
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
References
► | URL | Tags | |||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
|
{ "containers": { "adp": [ { "providerMetadata": { "dateUpdated": "2024-08-04T16:55:10.629Z", "orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE" }, "references": [ { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" }, { "tags": [ "x_refsource_MISC", "x_transferred" ], "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" } ], "title": "CVE Program Container" } ], "cna": { "affected": [ { "product": "n/a", "vendor": "n/a", "versions": [ { "status": "affected", "version": "n/a" } ] } ], "descriptions": [ { "lang": "en", "value": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3." } ], "problemTypes": [ { "descriptions": [ { "description": "n/a", "lang": "en", "type": "text" } ] } ], "providerMetadata": { "dateUpdated": "2020-12-15T22:15:35", "orgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "shortName": "mitre" }, "references": [ { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" }, { "tags": [ "x_refsource_MISC" ], "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" } ], "x_legacyV4Record": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2020-29663", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2", "refsource": "MISC", "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" }, { "name": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6", "refsource": "MISC", "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" } ] } } } }, "cveMetadata": { "assignerOrgId": "8254265b-2729-46b6-b9e3-3dfca2d5bfca", "assignerShortName": "mitre", "cveId": "CVE-2020-29663", "datePublished": "2020-12-15T22:15:35", "dateReserved": "2020-12-09T00:00:00", "dateUpdated": "2024-08-04T16:55:10.629Z", "state": "PUBLISHED" }, "dataType": "CVE_RECORD", "dataVersion": "5.1", "vulnerability-lookup:meta": { "nvd": "{\"cve\":{\"id\":\"CVE-2020-29663\",\"sourceIdentifier\":\"cve@mitre.org\",\"published\":\"2020-12-15T23:15:12.780\",\"lastModified\":\"2024-11-21T05:24:23.457\",\"vulnStatus\":\"Modified\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.\"},{\"lang\":\"es\",\"value\":\"Icinga versiones 2 v2.8.0 hasta v2.11.7 y versi\u00f3n v2.12.2, presenta un problema en donde los certificados revocados que deben renovarse ser\u00e1n renovados autom\u00e1ticamente, ignorando la CRL.\u0026#xa0;Este problema es corregido en Icinga versiones 2 v2.11.8 y v2.12.3\"}],\"metrics\":{\"cvssMetricV31\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"3.1\",\"vectorString\":\"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N\",\"baseScore\":9.1,\"baseSeverity\":\"CRITICAL\",\"attackVector\":\"NETWORK\",\"attackComplexity\":\"LOW\",\"privilegesRequired\":\"NONE\",\"userInteraction\":\"NONE\",\"scope\":\"UNCHANGED\",\"confidentialityImpact\":\"HIGH\",\"integrityImpact\":\"HIGH\",\"availabilityImpact\":\"NONE\"},\"exploitabilityScore\":3.9,\"impactScore\":5.2}],\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:L/Au:N/C:P/I:P/A:N\",\"baseScore\":6.4,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"LOW\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"NONE\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":10.0,\"impactScore\":4.9,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"CWE-295\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*\",\"versionStartIncluding\":\"2.8.0\",\"versionEndIncluding\":\"2.11.7\",\"matchCriteriaId\":\"44D41D7C-A345-45EB-8614-6AA652C283FC\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:icinga:icinga:2.12.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"741BA635-D264-457A-8B20-01D19EDD612C\"}]}]}],\"references\":[{\"url\":\"https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2\",\"source\":\"cve@mitre.org\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6\",\"source\":\"cve@mitre.org\",\"tags\":[\"Third Party Advisory\"]},{\"url\":\"https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Patch\",\"Third Party Advisory\"]},{\"url\":\"https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Third Party Advisory\"]}]}}" } }
suse-su-2022:3725-1
Vulnerability from csaf_suse
Published
2022-10-25 10:49
Modified
2022-10-25 10:49
Summary
Security update for icinga2
Notes
Title of the patch
Security update for icinga2
Description of the patch
This update for icinga2 fixes the following issues:
- CVE-2020-14004: prepare-dirs script allows for symlink attack in the icinga user context. (bsc#1172171)
- CVE-2020-29663: ignoring CRL, where revoked certificates due for renewal will automatically be renewed. (bsc#281137)
- CVE-2021-37698: Missing TLS server certificate validation in ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer. (bsc#281137)
Patchnames
SUSE-2022-3725,SUSE-SLE-Module-HPC-12-2022-3725
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "important" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for icinga2", "title": "Title of the patch" }, { "category": "description", "text": "This update for icinga2 fixes the following issues:\n\n- CVE-2020-14004: prepare-dirs script allows for symlink attack in the icinga user context. (bsc#1172171)\n- CVE-2020-29663: ignoring CRL, where revoked certificates due for renewal will automatically be renewed. (bsc#281137)\n- CVE-2021-37698: Missing TLS server certificate validation in ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer. (bsc#281137)\n", "title": "Description of the patch" }, { "category": "details", "text": "SUSE-2022-3725,SUSE-SLE-Module-HPC-12-2022-3725", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/suse-su-2022_3725-1.json" }, { "category": "self", "summary": "URL for SUSE-SU-2022:3725-1", "url": "https://www.suse.com/support/update/announcement/2022/suse-su-20223725-1/" }, { "category": "self", "summary": "E-Mail link for SUSE-SU-2022:3725-1", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-October/012665.html" }, { "category": "self", "summary": "SUSE Bug 1172171", "url": "https://bugzilla.suse.com/1172171" }, { "category": "self", "summary": "SUSE Bug 1180147", "url": "https://bugzilla.suse.com/1180147" }, { "category": "self", "summary": "SUSE Bug 1189653", "url": "https://bugzilla.suse.com/1189653" }, { "category": "self", "summary": "SUSE CVE CVE-2020-14004 page", "url": "https://www.suse.com/security/cve/CVE-2020-14004/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-37698 page", "url": "https://www.suse.com/security/cve/CVE-2021-37698/" } ], "title": "Security update for icinga2", "tracking": { "current_release_date": "2022-10-25T10:49:03Z", "generator": { "date": "2022-10-25T10:49:03Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "SUSE-SU-2022:3725-1", "initial_release_date": "2022-10-25T10:49:03Z", "revision_history": [ { "date": "2022-10-25T10:49:03Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-2.8.2-3.6.1.aarch64", "product_id": "icinga2-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-bin-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-bin-2.8.2-3.6.1.aarch64", "product_id": "icinga2-bin-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-common-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-common-2.8.2-3.6.1.aarch64", "product_id": "icinga2-common-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-doc-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-doc-2.8.2-3.6.1.aarch64", "product_id": "icinga2-doc-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "product_id": "icinga2-ido-mysql-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "product_id": "icinga2-ido-pgsql-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-libs-2.8.2-3.6.1.aarch64", "product": { "name": "icinga2-libs-2.8.2-3.6.1.aarch64", "product_id": "icinga2-libs-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "nano-icinga2-2.8.2-3.6.1.aarch64", "product": { "name": "nano-icinga2-2.8.2-3.6.1.aarch64", "product_id": "nano-icinga2-2.8.2-3.6.1.aarch64" } }, { "category": "product_version", "name": "vim-icinga2-2.8.2-3.6.1.aarch64", "product": { "name": "vim-icinga2-2.8.2-3.6.1.aarch64", "product_id": "vim-icinga2-2.8.2-3.6.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.8.2-3.6.1.i586", "product": { "name": "icinga2-2.8.2-3.6.1.i586", "product_id": "icinga2-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "icinga2-bin-2.8.2-3.6.1.i586", "product": { "name": "icinga2-bin-2.8.2-3.6.1.i586", "product_id": "icinga2-bin-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "icinga2-common-2.8.2-3.6.1.i586", "product": { "name": "icinga2-common-2.8.2-3.6.1.i586", "product_id": "icinga2-common-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "icinga2-doc-2.8.2-3.6.1.i586", "product": { "name": "icinga2-doc-2.8.2-3.6.1.i586", "product_id": "icinga2-doc-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.8.2-3.6.1.i586", "product": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.i586", "product_id": "icinga2-ido-mysql-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.8.2-3.6.1.i586", "product": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.i586", "product_id": "icinga2-ido-pgsql-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "icinga2-libs-2.8.2-3.6.1.i586", "product": { "name": "icinga2-libs-2.8.2-3.6.1.i586", "product_id": "icinga2-libs-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "nano-icinga2-2.8.2-3.6.1.i586", "product": { "name": "nano-icinga2-2.8.2-3.6.1.i586", "product_id": "nano-icinga2-2.8.2-3.6.1.i586" } }, { "category": "product_version", "name": "vim-icinga2-2.8.2-3.6.1.i586", "product": { "name": "vim-icinga2-2.8.2-3.6.1.i586", "product_id": "vim-icinga2-2.8.2-3.6.1.i586" } } ], "category": "architecture", "name": "i586" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-bin-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-bin-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-bin-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-common-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-common-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-common-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-doc-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-doc-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-doc-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-ido-mysql-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-ido-pgsql-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-libs-2.8.2-3.6.1.ppc64le", "product": { "name": "icinga2-libs-2.8.2-3.6.1.ppc64le", "product_id": "icinga2-libs-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "nano-icinga2-2.8.2-3.6.1.ppc64le", "product": { "name": "nano-icinga2-2.8.2-3.6.1.ppc64le", "product_id": "nano-icinga2-2.8.2-3.6.1.ppc64le" } }, { "category": "product_version", "name": "vim-icinga2-2.8.2-3.6.1.ppc64le", "product": { "name": "vim-icinga2-2.8.2-3.6.1.ppc64le", "product_id": "vim-icinga2-2.8.2-3.6.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.8.2-3.6.1.s390", "product": { "name": "icinga2-2.8.2-3.6.1.s390", "product_id": "icinga2-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "icinga2-bin-2.8.2-3.6.1.s390", "product": { "name": "icinga2-bin-2.8.2-3.6.1.s390", "product_id": "icinga2-bin-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "icinga2-common-2.8.2-3.6.1.s390", "product": { "name": "icinga2-common-2.8.2-3.6.1.s390", "product_id": "icinga2-common-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "icinga2-doc-2.8.2-3.6.1.s390", "product": { "name": "icinga2-doc-2.8.2-3.6.1.s390", "product_id": "icinga2-doc-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.8.2-3.6.1.s390", "product": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.s390", "product_id": "icinga2-ido-mysql-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.8.2-3.6.1.s390", "product": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.s390", "product_id": "icinga2-ido-pgsql-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "icinga2-libs-2.8.2-3.6.1.s390", "product": { "name": "icinga2-libs-2.8.2-3.6.1.s390", "product_id": "icinga2-libs-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "nano-icinga2-2.8.2-3.6.1.s390", "product": { "name": "nano-icinga2-2.8.2-3.6.1.s390", "product_id": "nano-icinga2-2.8.2-3.6.1.s390" } }, { "category": "product_version", "name": "vim-icinga2-2.8.2-3.6.1.s390", "product": { "name": "vim-icinga2-2.8.2-3.6.1.s390", "product_id": "vim-icinga2-2.8.2-3.6.1.s390" } } ], "category": "architecture", "name": "s390" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-2.8.2-3.6.1.s390x", "product_id": "icinga2-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "icinga2-bin-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-bin-2.8.2-3.6.1.s390x", "product_id": "icinga2-bin-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "icinga2-common-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-common-2.8.2-3.6.1.s390x", "product_id": "icinga2-common-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "icinga2-doc-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-doc-2.8.2-3.6.1.s390x", "product_id": "icinga2-doc-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.s390x", "product_id": "icinga2-ido-mysql-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.s390x", "product_id": "icinga2-ido-pgsql-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "icinga2-libs-2.8.2-3.6.1.s390x", "product": { "name": "icinga2-libs-2.8.2-3.6.1.s390x", "product_id": "icinga2-libs-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "nano-icinga2-2.8.2-3.6.1.s390x", "product": { "name": "nano-icinga2-2.8.2-3.6.1.s390x", "product_id": "nano-icinga2-2.8.2-3.6.1.s390x" } }, { "category": "product_version", "name": "vim-icinga2-2.8.2-3.6.1.s390x", "product": { "name": "vim-icinga2-2.8.2-3.6.1.s390x", "product_id": "vim-icinga2-2.8.2-3.6.1.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-2.8.2-3.6.1.x86_64", "product_id": "icinga2-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-bin-2.8.2-3.6.1.x86_64", "product_id": "icinga2-bin-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-common-2.8.2-3.6.1.x86_64", "product_id": "icinga2-common-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-doc-2.8.2-3.6.1.x86_64", "product_id": "icinga2-doc-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "product_id": "icinga2-ido-mysql-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "product_id": "icinga2-ido-pgsql-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-libs-2.8.2-3.6.1.x86_64", "product": { "name": "icinga2-libs-2.8.2-3.6.1.x86_64", "product_id": "icinga2-libs-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.8.2-3.6.1.x86_64", "product": { "name": "nano-icinga2-2.8.2-3.6.1.x86_64", "product_id": "nano-icinga2-2.8.2-3.6.1.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.8.2-3.6.1.x86_64", "product": { "name": "vim-icinga2-2.8.2-3.6.1.x86_64", "product_id": "vim-icinga2-2.8.2-3.6.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux Enterprise Module for HPC 12", "product": { "name": "SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12", "product_identification_helper": { "cpe": "cpe:/o:suse:sle-module-hpc:12" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-bin-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-bin-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-common-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-common-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-doc-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-doc-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-libs-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64" }, "product_reference": "icinga2-libs-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-libs-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64" }, "product_reference": "icinga2-libs-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.8.2-3.6.1.aarch64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64" }, "product_reference": "vim-icinga2-2.8.2-3.6.1.aarch64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.8.2-3.6.1.x86_64 as component of SUSE Linux Enterprise Module for HPC 12", "product_id": "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" }, "product_reference": "vim-icinga2-2.8.2-3.6.1.x86_64", "relates_to_product_reference": "SUSE Linux Enterprise Module for HPC 12" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-14004", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-14004" } ], "notes": [ { "category": "general", "text": "An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-14004", "url": "https://www.suse.com/security/cve/CVE-2020-14004" }, { "category": "external", "summary": "SUSE Bug 1172171 for CVE-2020-14004", "url": "https://bugzilla.suse.com/1172171" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2022-10-25T10:49:03Z", "details": "important" } ], "title": "CVE-2020-14004" }, { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2022-10-25T10:49:03Z", "details": "moderate" } ], "title": "CVE-2020-29663" }, { "cve": "CVE-2021-37698", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-37698" } ], "notes": [ { "category": "general", "text": "Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server\u0027s certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mentioned time series databases (TSDBs) using TLS over a spoofable infrastructure should immediately upgrade to version 2.13.1, 2.12.6, or 2.11.11 to patch the issue. Such instances should also change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB. There are no workarounds aside from upgrading.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-37698", "url": "https://www.suse.com/security/cve/CVE-2021-37698" }, { "category": "external", "summary": "SUSE Bug 1189653 for CVE-2021-37698", "url": "https://bugzilla.suse.com/1189653" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" }, "products": [ "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-bin-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-common-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-doc-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-mysql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-ido-pgsql-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:icinga2-libs-2.8.2-3.6.1.x86_64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.aarch64", "SUSE Linux Enterprise Module for HPC 12:vim-icinga2-2.8.2-3.6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2022-10-25T10:49:03Z", "details": "moderate" } ], "title": "CVE-2021-37698" } ] }
opensuse-su-2024:10856-1
Vulnerability from csaf_opensuse
Published
2024-06-15 00:00
Modified
2024-06-15 00:00
Summary
icinga2-2.13.1-1.3 on GA media
Notes
Title of the patch
icinga2-2.13.1-1.3 on GA media
Description of the patch
These are all security issues fixed in the icinga2-2.13.1-1.3 package on the GA media of openSUSE Tumbleweed.
Patchnames
openSUSE-Tumbleweed-2024-10856
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "icinga2-2.13.1-1.3 on GA media", "title": "Title of the patch" }, { "category": "description", "text": "These are all security issues fixed in the icinga2-2.13.1-1.3 package on the GA media of openSUSE Tumbleweed.", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-Tumbleweed-2024-10856", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2024_10856-1.json" }, { "category": "self", "summary": "SUSE CVE CVE-2017-16933 page", "url": "https://www.suse.com/security/cve/CVE-2017-16933/" }, { "category": "self", "summary": "SUSE CVE CVE-2018-6534 page", "url": "https://www.suse.com/security/cve/CVE-2018-6534/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-14004 page", "url": "https://www.suse.com/security/cve/CVE-2020-14004/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-32739 page", "url": "https://www.suse.com/security/cve/CVE-2021-32739/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-32743 page", "url": "https://www.suse.com/security/cve/CVE-2021-32743/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-37698 page", "url": "https://www.suse.com/security/cve/CVE-2021-37698/" } ], "title": "icinga2-2.13.1-1.3 on GA media", "tracking": { "current_release_date": "2024-06-15T00:00:00Z", "generator": { "date": "2024-06-15T00:00:00Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2024:10856-1", "initial_release_date": "2024-06-15T00:00:00Z", "revision_history": [ { "date": "2024-06-15T00:00:00Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.13.1-1.3.aarch64", "product": { "name": "icinga2-2.13.1-1.3.aarch64", "product_id": "icinga2-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "icinga2-bin-2.13.1-1.3.aarch64", "product": { "name": "icinga2-bin-2.13.1-1.3.aarch64", "product_id": "icinga2-bin-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "icinga2-common-2.13.1-1.3.aarch64", "product": { "name": "icinga2-common-2.13.1-1.3.aarch64", "product_id": "icinga2-common-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "icinga2-doc-2.13.1-1.3.aarch64", "product": { "name": "icinga2-doc-2.13.1-1.3.aarch64", "product_id": "icinga2-doc-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.13.1-1.3.aarch64", "product": { "name": "icinga2-ido-mysql-2.13.1-1.3.aarch64", "product_id": "icinga2-ido-mysql-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.13.1-1.3.aarch64", "product": { "name": "icinga2-ido-pgsql-2.13.1-1.3.aarch64", "product_id": "icinga2-ido-pgsql-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "nano-icinga2-2.13.1-1.3.aarch64", "product": { "name": "nano-icinga2-2.13.1-1.3.aarch64", "product_id": "nano-icinga2-2.13.1-1.3.aarch64" } }, { "category": "product_version", "name": "vim-icinga2-2.13.1-1.3.aarch64", "product": { "name": "vim-icinga2-2.13.1-1.3.aarch64", "product_id": "vim-icinga2-2.13.1-1.3.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.13.1-1.3.ppc64le", "product": { "name": "icinga2-2.13.1-1.3.ppc64le", "product_id": "icinga2-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "icinga2-bin-2.13.1-1.3.ppc64le", "product": { "name": "icinga2-bin-2.13.1-1.3.ppc64le", "product_id": "icinga2-bin-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "icinga2-common-2.13.1-1.3.ppc64le", "product": { "name": "icinga2-common-2.13.1-1.3.ppc64le", "product_id": "icinga2-common-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "icinga2-doc-2.13.1-1.3.ppc64le", "product": { "name": "icinga2-doc-2.13.1-1.3.ppc64le", "product_id": "icinga2-doc-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.13.1-1.3.ppc64le", "product": { "name": "icinga2-ido-mysql-2.13.1-1.3.ppc64le", "product_id": "icinga2-ido-mysql-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "product": { "name": "icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "product_id": "icinga2-ido-pgsql-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "nano-icinga2-2.13.1-1.3.ppc64le", "product": { "name": "nano-icinga2-2.13.1-1.3.ppc64le", "product_id": "nano-icinga2-2.13.1-1.3.ppc64le" } }, { "category": "product_version", "name": "vim-icinga2-2.13.1-1.3.ppc64le", "product": { "name": "vim-icinga2-2.13.1-1.3.ppc64le", "product_id": "vim-icinga2-2.13.1-1.3.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.13.1-1.3.s390x", "product": { "name": "icinga2-2.13.1-1.3.s390x", "product_id": "icinga2-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "icinga2-bin-2.13.1-1.3.s390x", "product": { "name": "icinga2-bin-2.13.1-1.3.s390x", "product_id": "icinga2-bin-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "icinga2-common-2.13.1-1.3.s390x", "product": { "name": "icinga2-common-2.13.1-1.3.s390x", "product_id": "icinga2-common-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "icinga2-doc-2.13.1-1.3.s390x", "product": { "name": "icinga2-doc-2.13.1-1.3.s390x", "product_id": "icinga2-doc-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.13.1-1.3.s390x", "product": { "name": "icinga2-ido-mysql-2.13.1-1.3.s390x", "product_id": "icinga2-ido-mysql-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.13.1-1.3.s390x", "product": { "name": "icinga2-ido-pgsql-2.13.1-1.3.s390x", "product_id": "icinga2-ido-pgsql-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "nano-icinga2-2.13.1-1.3.s390x", "product": { "name": "nano-icinga2-2.13.1-1.3.s390x", "product_id": "nano-icinga2-2.13.1-1.3.s390x" } }, { "category": "product_version", "name": "vim-icinga2-2.13.1-1.3.s390x", "product": { "name": "vim-icinga2-2.13.1-1.3.s390x", "product_id": "vim-icinga2-2.13.1-1.3.s390x" } } ], "category": "architecture", "name": "s390x" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.13.1-1.3.x86_64", "product": { "name": "icinga2-2.13.1-1.3.x86_64", "product_id": "icinga2-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.13.1-1.3.x86_64", "product": { "name": "icinga2-bin-2.13.1-1.3.x86_64", "product_id": "icinga2-bin-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.13.1-1.3.x86_64", "product": { "name": "icinga2-common-2.13.1-1.3.x86_64", "product_id": "icinga2-common-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.13.1-1.3.x86_64", "product": { "name": "icinga2-doc-2.13.1-1.3.x86_64", "product_id": "icinga2-doc-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.13.1-1.3.x86_64", "product": { "name": "icinga2-ido-mysql-2.13.1-1.3.x86_64", "product_id": "icinga2-ido-mysql-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.13.1-1.3.x86_64", "product": { "name": "icinga2-ido-pgsql-2.13.1-1.3.x86_64", "product_id": "icinga2-ido-pgsql-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.13.1-1.3.x86_64", "product": { "name": "nano-icinga2-2.13.1-1.3.x86_64", "product_id": "nano-icinga2-2.13.1-1.3.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.13.1-1.3.x86_64", "product": { "name": "vim-icinga2-2.13.1-1.3.x86_64", "product_id": "vim-icinga2-2.13.1-1.3.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Tumbleweed", "product": { "name": "openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed", "product_identification_helper": { "cpe": "cpe:/o:opensuse:tumbleweed" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64" }, "product_reference": "icinga2-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le" }, "product_reference": "icinga2-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x" }, "product_reference": "icinga2-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64" }, "product_reference": "icinga2-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64" }, "product_reference": "icinga2-bin-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le" }, "product_reference": "icinga2-bin-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x" }, "product_reference": "icinga2-bin-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64" }, "product_reference": "icinga2-bin-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64" }, "product_reference": "icinga2-common-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le" }, "product_reference": "icinga2-common-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x" }, "product_reference": "icinga2-common-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64" }, "product_reference": "icinga2-common-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64" }, "product_reference": "icinga2-doc-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le" }, "product_reference": "icinga2-doc-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x" }, "product_reference": "icinga2-doc-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64" }, "product_reference": "icinga2-doc-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64" }, "product_reference": "icinga2-ido-mysql-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x" }, "product_reference": "icinga2-ido-mysql-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64" }, "product_reference": "icinga2-ido-mysql-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x" }, "product_reference": "icinga2-ido-pgsql-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64" }, "product_reference": "nano-icinga2-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le" }, "product_reference": "nano-icinga2-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x" }, "product_reference": "nano-icinga2-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64" }, "product_reference": "nano-icinga2-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.13.1-1.3.aarch64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64" }, "product_reference": "vim-icinga2-2.13.1-1.3.aarch64", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.13.1-1.3.ppc64le as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le" }, "product_reference": "vim-icinga2-2.13.1-1.3.ppc64le", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.13.1-1.3.s390x as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x" }, "product_reference": "vim-icinga2-2.13.1-1.3.s390x", "relates_to_product_reference": "openSUSE Tumbleweed" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.13.1-1.3.x86_64 as component of openSUSE Tumbleweed", "product_id": "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" }, "product_reference": "vim-icinga2-2.13.1-1.3.x86_64", "relates_to_product_reference": "openSUSE Tumbleweed" } ] }, "vulnerabilities": [ { "cve": "CVE-2017-16933", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2017-16933" } ], "notes": [ { "category": "general", "text": "etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2017-16933", "url": "https://www.suse.com/security/cve/CVE-2017-16933" }, { "category": "external", "summary": "SUSE Bug 1086673 for CVE-2017-16933", "url": "https://bugzilla.suse.com/1086673" }, { "category": "external", "summary": "SUSE Bug 1086676 for CVE-2017-16933", "url": "https://bugzilla.suse.com/1086676" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7, "baseSeverity": "HIGH", "vectorString": "CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2017-16933" }, { "cve": "CVE-2018-6534", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2018-6534" } ], "notes": [ { "category": "general", "text": "An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted messages, an attacker can cause a NULL pointer dereference, which can cause the product to crash.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2018-6534", "url": "https://www.suse.com/security/cve/CVE-2018-6534" }, { "category": "external", "summary": "SUSE Bug 1086674 for CVE-2018-6534", "url": "https://bugzilla.suse.com/1086674" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.5, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H", "version": "3.0" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2018-6534" }, { "cve": "CVE-2020-14004", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-14004" } ], "notes": [ { "category": "general", "text": "An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-14004", "url": "https://www.suse.com/security/cve/CVE-2020-14004" }, { "category": "external", "summary": "SUSE Bug 1172171 for CVE-2020-14004", "url": "https://bugzilla.suse.com/1172171" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 7.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "important" } ], "title": "CVE-2020-14004" }, { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2020-29663" }, { "cve": "CVE-2021-32739", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-32739" } ], "notes": [ { "category": "general", "text": "Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user\u0027s credentials, an attacker can view most attributes of all config objects including `ticket_salt` of `ApiListener`. This salt is enough to compute a ticket for every possible common name (CN). A ticket, the master node\u0027s certificate, and a self-signed certificate are enough to successfully request the desired certificate from Icinga. That certificate may in turn be used to steal an endpoint or API user\u0027s identity. Versions 2.12.5 and 2.11.10 both contain a fix the vulnerability. As a workaround, one may either specify queryable types explicitly or filter out ApiListener objects.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-32739", "url": "https://www.suse.com/security/cve/CVE-2021-32739" }, { "category": "external", "summary": "SUSE Bug 1188372 for CVE-2021-32739", "url": "https://bugzilla.suse.com/1188372" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2021-32739" }, { "cve": "CVE-2021-32743", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-32743" } ], "notes": [ { "category": "general", "text": "Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions for the corresponding object types. IdoMysqlConnection and IdoPgsqlConnection (every released version) exposes the password of the user used to connect to the database. IcingaDB (added in 2.12.0) exposes the password used to connect to the Redis server. ElasticsearchWriter (added in 2.8.0)exposes the password used to connect to the Elasticsearch server. An attacker who obtains these credentials can impersonate Icinga to these services and add, modify and delete information there. If credentials with more permissions are in use, this increases the impact accordingly. Starting with the 2.11.10 and 2.12.5 releases, these passwords are no longer exposed via the API. As a workaround, API user permissions can be restricted to not allow querying of any affected objects, either by explicitly listing only the required object types for object query permissions, or by applying a filter rule.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-32743", "url": "https://www.suse.com/security/cve/CVE-2021-32743" }, { "category": "external", "summary": "SUSE Bug 1188370 for CVE-2021-32743", "url": "https://bugzilla.suse.com/1188370" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2021-32743" }, { "cve": "CVE-2021-37698", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-37698" } ], "notes": [ { "category": "general", "text": "Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions 2.5.0 through 2.13.0, ElasticsearchWriter, GelfWriter, InfluxdbWriter and Influxdb2Writer do not verify the server\u0027s certificate despite a certificate authority being specified. Icinga 2 instances which connect to any of the mentioned time series databases (TSDBs) using TLS over a spoofable infrastructure should immediately upgrade to version 2.13.1, 2.12.6, or 2.11.11 to patch the issue. Such instances should also change the credentials (if any) used by the TSDB writer feature to authenticate against the TSDB. There are no workarounds aside from upgrading.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-37698", "url": "https://www.suse.com/security/cve/CVE-2021-37698" }, { "category": "external", "summary": "SUSE Bug 1189653 for CVE-2021-37698", "url": "https://bugzilla.suse.com/1189653" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 6.8, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N", "version": "3.1" }, "products": [ "openSUSE Tumbleweed:icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-bin-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-common-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-doc-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-mysql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.s390x", "openSUSE Tumbleweed:icinga2-ido-pgsql-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:nano-icinga2-2.13.1-1.3.x86_64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.aarch64", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.ppc64le", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.s390x", "openSUSE Tumbleweed:vim-icinga2-2.13.1-1.3.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2024-06-15T00:00:00Z", "details": "moderate" } ], "title": "CVE-2021-37698" } ] }
opensuse-su-2021:1069-1
Vulnerability from csaf_opensuse
Published
2021-07-20 22:06
Modified
2021-07-20 22:06
Summary
Security update for icinga2
Notes
Title of the patch
Security update for icinga2
Description of the patch
This update for icinga2 fixes the following issues:
Update to 2.12.4
* Bugfixes
- Fix a crash when notification objects are deleted using the
API #8782
- Fix crashes that might occur during downtime scheduling if
host or downtime objects are deleted using the API #8785
- Fix an issue where notifications may incorrectly be skipped
after a downtime ends #8775
- Don't send reminder notification if the notification is still
suppressed by a time period #8808
- Fix an issue where attempting to create a duplicate object
using the API might result in the original object being
deleted #8787
- IDO: prioritize program status updates #8809
- Improve exceptions handling, including a fix for an uncaught
exception on Windows #8777
- Retry file rename operations on Windows to avoid intermittent
locking issues #8771
* Enhancements
- Support Boost 1.74 (Ubuntu 21.04, Fedora 34) #8792
Update to 2.12.3
* Security
- Fix that revoked certificates due for renewal will
automatically be renewed ignoring the CRL
(Advisory / CVE-2020-29663 - fixes boo#1180147 )
* Bugfixes
- Improve config sync locking - resolves high load issues on
Windows #8511
- Fix runtime config updates being ignored for objects without
zone #8549
- Use proper buffer size for OpenSSL error messages #8542
* Enhancements
- On checkable recovery: re-check children that have a problem
#8506
Update to 2.12.2
* Bugfixes
- Fix a connection leak with misconfigured agents #8483
- Properly sync changes of config objects in global zones done
via the API #8474 #8470
- Prevent other clients from being disconnected when replaying
the cluster log takes very long #8496
- Avoid duplicate connections between endpoints #8465
- Ignore incoming config object updates for unknown zones #8461
- Check timestamps before removing files in config sync #8495
* Enhancements
- Include HTTP status codes in log #8467
Patchnames
openSUSE-2021-1069
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for icinga2", "title": "Title of the patch" }, { "category": "description", "text": "This update for icinga2 fixes the following issues:\n\nUpdate to 2.12.4\n\n * Bugfixes\n\n - Fix a crash when notification objects are deleted using the\n API #8782\n - Fix crashes that might occur during downtime scheduling if\n host or downtime objects are deleted using the API #8785\n - Fix an issue where notifications may incorrectly be skipped\n after a downtime ends #8775\n - Don\u0027t send reminder notification if the notification is still\n suppressed by a time period #8808\n - Fix an issue where attempting to create a duplicate object\n using the API might result in the original object being\n deleted #8787\n - IDO: prioritize program status updates #8809\n - Improve exceptions handling, including a fix for an uncaught\n exception on Windows #8777\n - Retry file rename operations on Windows to avoid intermittent\n locking issues #8771\n\n * Enhancements\n\n - Support Boost 1.74 (Ubuntu 21.04, Fedora 34) #8792\n\nUpdate to 2.12.3\n\n * Security\n\n - Fix that revoked certificates due for renewal will \n automatically be renewed ignoring the CRL \n (Advisory / CVE-2020-29663 - fixes boo#1180147 )\n\n * Bugfixes\n\n - Improve config sync locking - resolves high load issues on\n Windows #8511\n - Fix runtime config updates being ignored for objects without\n zone #8549\n - Use proper buffer size for OpenSSL error messages #8542\n\n * Enhancements\n\n - On checkable recovery: re-check children that have a problem\n #8506\n\nUpdate to 2.12.2\n\n * Bugfixes\n\n - Fix a connection leak with misconfigured agents #8483\n - Properly sync changes of config objects in global zones done\n via the API #8474 #8470\n - Prevent other clients from being disconnected when replaying\n the cluster log takes very long #8496\n - Avoid duplicate connections between endpoints #8465\n - Ignore incoming config object updates for unknown zones #8461\n - Check timestamps before removing files in config sync #8495\n\n * Enhancements\n\n - Include HTTP status codes in log #8467\n", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2021-1069", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_1069-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2021:1069-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7RXCOMXKKWZ7PYODPH5SO5SSBKRXIJWA/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2021:1069-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/7RXCOMXKKWZ7PYODPH5SO5SSBKRXIJWA/" }, { "category": "self", "summary": "SUSE Bug 1180147", "url": "https://bugzilla.suse.com/1180147" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" } ], "title": "Security update for icinga2", "tracking": { "current_release_date": "2021-07-20T22:06:19Z", "generator": { "date": "2021-07-20T22:06:19Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2021:1069-1", "initial_release_date": "2021-07-20T22:06:19Z", "revision_history": [ { "date": "2021-07-20T22:06:19Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "icinga2-2.12.4-bp153.2.3.1.aarch64", "product_id": "icinga2-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "product_id": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "icinga2-common-2.12.4-bp153.2.3.1.aarch64", "product_id": "icinga2-common-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "product_id": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "product_id": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "product_id": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "product_id": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "product": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "product_id": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "icinga2-2.12.4-bp153.2.3.1.ppc64le", "product_id": "icinga2-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "product_id": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "product_id": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "product_id": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "product_id": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "product_id": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "product_id": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "product": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "product_id": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "icinga2-2.12.4-bp153.2.3.1.x86_64", "product_id": "icinga2-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "product_id": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "icinga2-common-2.12.4-bp153.2.3.1.x86_64", "product_id": "icinga2-common-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "product_id": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "product_id": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "product_id": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "product_id": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "product": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "product_id": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Package Hub 15 SP3", "product": { "name": "SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3" } }, { "category": "product_name", "name": "openSUSE Leap 15.3", "product": { "name": "openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.3" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-common-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-common-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-common-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-common-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64" }, "product_reference": "vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64" }, "product_reference": "vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.4-bp153.2.3.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.4-bp153.2.3.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-20T22:06:19Z", "details": "moderate" } ], "title": "CVE-2020-29663" } ] }
opensuse-su-2021:1053-1
Vulnerability from csaf_opensuse
Published
2021-07-19 10:06
Modified
2021-07-19 10:06
Summary
Security update for icinga2
Notes
Title of the patch
Security update for icinga2
Description of the patch
This update for icinga2 fixes the following issues:
icinga2 was updated to 2.12.4
* Bugfixes
- Fix a crash when notification objects are deleted using the
API #8782
- Fix crashes that might occur during downtime scheduling if
host or downtime objects are deleted using the API #8785
- Fix an issue where notifications may incorrectly be skipped
after a downtime ends #8775
- Don't send reminder notification if the notification is still
suppressed by a time period #8808
- Fix an issue where attempting to create a duplicate object
using the API might result in the original object being
deleted #8787
- IDO: prioritize program status updates #8809
- Improve exceptions handling, including a fix for an uncaught
exception on Windows #8777
- Retry file rename operations on Windows to avoid intermittent
locking issues #8771
Update to 2.12.3
* Security
- Fix that revoked certificates due for renewal will
automatically be renewed ignoring the CRL
(Advisory / CVE-2020-29663 - fixes boo#1180147 )
* Bugfixes
- Improve config sync locking - resolves high load issues on
Windows #8511
- Fix runtime config updates being ignored for objects without
zone #8549
- Use proper buffer size for OpenSSL error messages #8542
* Enhancements
- On checkable recovery: re-check children that have a problem
#8506
Update to 2.12.2
* Bugfixes
- Fix a connection leak with misconfigured agents #8483
- Properly sync changes of config objects in global zones done
via the API #8474 #8470
- Prevent other clients from being disconnected when replaying
the cluster log takes very long #8496
- Avoid duplicate connections between endpoints #8465
- Ignore incoming config object updates for unknown zones #8461
- Check timestamps before removing files in config sync #8495
* Enhancements
- Include HTTP status codes in log #8467
Patchnames
openSUSE-2021-1053
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for icinga2", "title": "Title of the patch" }, { "category": "description", "text": "This update for icinga2 fixes the following issues:\n\nicinga2 was updated to 2.12.4\n\n * Bugfixes\n\n - Fix a crash when notification objects are deleted using the\n API #8782\n - Fix crashes that might occur during downtime scheduling if\n host or downtime objects are deleted using the API #8785\n - Fix an issue where notifications may incorrectly be skipped\n after a downtime ends #8775\n - Don\u0027t send reminder notification if the notification is still\n suppressed by a time period #8808\n - Fix an issue where attempting to create a duplicate object\n using the API might result in the original object being\n deleted #8787\n - IDO: prioritize program status updates #8809\n - Improve exceptions handling, including a fix for an uncaught\n exception on Windows #8777\n - Retry file rename operations on Windows to avoid intermittent\n locking issues #8771\n\nUpdate to 2.12.3\n\n * Security\n\n - Fix that revoked certificates due for renewal will \n automatically be renewed ignoring the CRL \n (Advisory / CVE-2020-29663 - fixes boo#1180147 )\n\n * Bugfixes\n\n - Improve config sync locking - resolves high load issues on\n Windows #8511\n - Fix runtime config updates being ignored for objects without\n zone #8549\n - Use proper buffer size for OpenSSL error messages #8542\n\n * Enhancements\n\n - On checkable recovery: re-check children that have a problem\n #8506\n\nUpdate to 2.12.2\n\n * Bugfixes\n\n - Fix a connection leak with misconfigured agents #8483\n - Properly sync changes of config objects in global zones done\n via the API #8474 #8470\n - Prevent other clients from being disconnected when replaying\n the cluster log takes very long #8496\n - Avoid duplicate connections between endpoints #8465\n - Ignore incoming config object updates for unknown zones #8461\n - Check timestamps before removing files in config sync #8495\n\n * Enhancements\n\n - Include HTTP status codes in log #8467\n", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2021-1053", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_1053-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2021:1053-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2MGD4GT6SSRCFTDAW4FIYGJF6HKJQ6AO/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2021:1053-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/2MGD4GT6SSRCFTDAW4FIYGJF6HKJQ6AO/" }, { "category": "self", "summary": "SUSE Bug 1180147", "url": "https://bugzilla.suse.com/1180147" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" } ], "title": "Security update for icinga2", "tracking": { "current_release_date": "2021-07-19T10:06:10Z", "generator": { "date": "2021-07-19T10:06:10Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2021:1053-1", "initial_release_date": "2021-07-19T10:06:10Z", "revision_history": [ { "date": "2021-07-19T10:06:10Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "icinga2-2.12.4-bp151.3.6.1.aarch64", "product_id": "icinga2-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "icinga2-bin-2.12.4-bp151.3.6.1.aarch64", "product_id": "icinga2-bin-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "icinga2-common-2.12.4-bp151.3.6.1.aarch64", "product_id": "icinga2-common-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "icinga2-doc-2.12.4-bp151.3.6.1.aarch64", "product_id": "icinga2-doc-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64", "product_id": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64", "product_id": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "nano-icinga2-2.12.4-bp151.3.6.1.aarch64", "product_id": "nano-icinga2-2.12.4-bp151.3.6.1.aarch64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp151.3.6.1.aarch64", "product": { "name": "vim-icinga2-2.12.4-bp151.3.6.1.aarch64", "product_id": "vim-icinga2-2.12.4-bp151.3.6.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "icinga2-2.12.4-bp151.3.6.1.ppc64le", "product_id": "icinga2-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "icinga2-bin-2.12.4-bp151.3.6.1.ppc64le", "product_id": "icinga2-bin-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "icinga2-common-2.12.4-bp151.3.6.1.ppc64le", "product_id": "icinga2-common-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "icinga2-doc-2.12.4-bp151.3.6.1.ppc64le", "product_id": "icinga2-doc-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le", "product_id": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le", "product_id": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "nano-icinga2-2.12.4-bp151.3.6.1.ppc64le", "product_id": "nano-icinga2-2.12.4-bp151.3.6.1.ppc64le" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp151.3.6.1.ppc64le", "product": { "name": "vim-icinga2-2.12.4-bp151.3.6.1.ppc64le", "product_id": "vim-icinga2-2.12.4-bp151.3.6.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "icinga2-2.12.4-bp151.3.6.1.x86_64", "product_id": "icinga2-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "icinga2-bin-2.12.4-bp151.3.6.1.x86_64", "product_id": "icinga2-bin-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "icinga2-common-2.12.4-bp151.3.6.1.x86_64", "product_id": "icinga2-common-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "icinga2-doc-2.12.4-bp151.3.6.1.x86_64", "product_id": "icinga2-doc-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64", "product_id": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64", "product_id": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "nano-icinga2-2.12.4-bp151.3.6.1.x86_64", "product_id": "nano-icinga2-2.12.4-bp151.3.6.1.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp151.3.6.1.x86_64", "product": { "name": "vim-icinga2-2.12.4-bp151.3.6.1.x86_64", "product_id": "vim-icinga2-2.12.4-bp151.3.6.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Package Hub 15 SP1", "product": { "name": "SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1" } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "icinga2-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "icinga2-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "icinga2-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "icinga2-bin-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "icinga2-bin-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "icinga2-common-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "icinga2-common-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "icinga2-common-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "icinga2-doc-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "icinga2-doc-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "nano-icinga2-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "nano-icinga2-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp151.3.6.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.aarch64" }, "product_reference": "vim-icinga2-2.12.4-bp151.3.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp151.3.6.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.4-bp151.3.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp151.3.6.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.x86_64" }, "product_reference": "vim-icinga2-2.12.4-bp151.3.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.4-bp151.3.6.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.4-bp151.3.6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-19T10:06:10Z", "details": "moderate" } ], "title": "CVE-2020-29663" } ] }
opensuse-su-2021:1054-1
Vulnerability from csaf_opensuse
Published
2021-07-19 10:06
Modified
2021-07-19 10:06
Summary
Security update for icinga2
Notes
Title of the patch
Security update for icinga2
Description of the patch
This update for icinga2 fixes the following issues:
Update to 2.12.4
* Bugfixes
- Fix a crash when notification objects are deleted using the
API #8782
- Fix crashes that might occur during downtime scheduling if
host or downtime objects are deleted using the API #8785
- Fix an issue where notifications may incorrectly be skipped
after a downtime ends #8775
- Don't send reminder notification if the notification is still
suppressed by a time period #8808
- Fix an issue where attempting to create a duplicate object
using the API might result in the original object being
deleted #8787
- IDO: prioritize program status updates #8809
- Improve exceptions handling, including a fix for an uncaught
exception on Windows #8777
- Retry file rename operations on Windows to avoid intermittent
locking issues #8771
* Enhancements
- Support Boost 1.74 (Ubuntu 21.04, Fedora 34) #8792
Update to 2.12.3
* Security
- Fix that revoked certificates due for renewal will
automatically be renewed ignoring the CRL
(Advisory / CVE-2020-29663 - fixes boo#1180147 )
* Bugfixes
- Improve config sync locking - resolves high load issues on
Windows #8511
- Fix runtime config updates being ignored for objects without
zone #8549
- Use proper buffer size for OpenSSL error messages #8542
* Enhancements
- On checkable recovery: re-check children that have a problem
#8506
Update to 2.12.2
* Bugfixes
- Fix a connection leak with misconfigured agents #8483
- Properly sync changes of config objects in global zones done
via the API #8474 #8470
- Prevent other clients from being disconnected when replaying
the cluster log takes very long #8496
- Avoid duplicate connections between endpoints #8465
- Ignore incoming config object updates for unknown zones #8461
- Check timestamps before removing files in config sync #8495
* Enhancements
- Include HTTP status codes in log #8467
Patchnames
openSUSE-2021-1054
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for icinga2", "title": "Title of the patch" }, { "category": "description", "text": "This update for icinga2 fixes the following issues:\n\nUpdate to 2.12.4\n\n * Bugfixes\n\n - Fix a crash when notification objects are deleted using the\n API #8782\n - Fix crashes that might occur during downtime scheduling if\n host or downtime objects are deleted using the API #8785\n - Fix an issue where notifications may incorrectly be skipped\n after a downtime ends #8775\n - Don\u0027t send reminder notification if the notification is still\n suppressed by a time period #8808\n - Fix an issue where attempting to create a duplicate object\n using the API might result in the original object being\n deleted #8787\n - IDO: prioritize program status updates #8809\n - Improve exceptions handling, including a fix for an uncaught\n exception on Windows #8777\n - Retry file rename operations on Windows to avoid intermittent\n locking issues #8771\n\n * Enhancements\n\n - Support Boost 1.74 (Ubuntu 21.04, Fedora 34) #8792\n\nUpdate to 2.12.3\n\n * Security\n\n - Fix that revoked certificates due for renewal will \n automatically be renewed ignoring the CRL \n (Advisory / CVE-2020-29663 - fixes boo#1180147 )\n\n * Bugfixes\n\n - Improve config sync locking - resolves high load issues on\n Windows #8511\n - Fix runtime config updates being ignored for objects without\n zone #8549\n - Use proper buffer size for OpenSSL error messages #8542\n * Enhancements\n - On checkable recovery: re-check children that have a problem\n #8506\n\nUpdate to 2.12.2\n\n * Bugfixes\n\n - Fix a connection leak with misconfigured agents #8483\n - Properly sync changes of config objects in global zones done\n via the API #8474 #8470\n - Prevent other clients from being disconnected when replaying\n the cluster log takes very long #8496\n - Avoid duplicate connections between endpoints #8465\n - Ignore incoming config object updates for unknown zones #8461\n - Check timestamps before removing files in config sync #8495\n\n * Enhancements\n\n - Include HTTP status codes in log #8467\n", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2021-1054", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_1054-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2021:1054-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XNOBY7TETKOOX2HQN4LHXGRCFGFAAFJC/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2021:1054-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/XNOBY7TETKOOX2HQN4LHXGRCFGFAAFJC/" }, { "category": "self", "summary": "SUSE Bug 1180147", "url": "https://bugzilla.suse.com/1180147" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" } ], "title": "Security update for icinga2", "tracking": { "current_release_date": "2021-07-19T10:06:13Z", "generator": { "date": "2021-07-19T10:06:13Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2021:1054-1", "initial_release_date": "2021-07-19T10:06:13Z", "revision_history": [ { "date": "2021-07-19T10:06:13Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "icinga2-2.12.4-bp152.4.6.1.aarch64", "product_id": "icinga2-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "icinga2-bin-2.12.4-bp152.4.6.1.aarch64", "product_id": "icinga2-bin-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "icinga2-common-2.12.4-bp152.4.6.1.aarch64", "product_id": "icinga2-common-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "icinga2-doc-2.12.4-bp152.4.6.1.aarch64", "product_id": "icinga2-doc-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64", "product_id": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64", "product_id": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "nano-icinga2-2.12.4-bp152.4.6.1.aarch64", "product_id": "nano-icinga2-2.12.4-bp152.4.6.1.aarch64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp152.4.6.1.aarch64", "product": { "name": "vim-icinga2-2.12.4-bp152.4.6.1.aarch64", "product_id": "vim-icinga2-2.12.4-bp152.4.6.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "icinga2-2.12.4-bp152.4.6.1.ppc64le", "product_id": "icinga2-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "icinga2-bin-2.12.4-bp152.4.6.1.ppc64le", "product_id": "icinga2-bin-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "icinga2-common-2.12.4-bp152.4.6.1.ppc64le", "product_id": "icinga2-common-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "icinga2-doc-2.12.4-bp152.4.6.1.ppc64le", "product_id": "icinga2-doc-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le", "product_id": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le", "product_id": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "nano-icinga2-2.12.4-bp152.4.6.1.ppc64le", "product_id": "nano-icinga2-2.12.4-bp152.4.6.1.ppc64le" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp152.4.6.1.ppc64le", "product": { "name": "vim-icinga2-2.12.4-bp152.4.6.1.ppc64le", "product_id": "vim-icinga2-2.12.4-bp152.4.6.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "icinga2-2.12.4-bp152.4.6.1.x86_64", "product_id": "icinga2-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "icinga2-bin-2.12.4-bp152.4.6.1.x86_64", "product_id": "icinga2-bin-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "icinga2-common-2.12.4-bp152.4.6.1.x86_64", "product_id": "icinga2-common-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "icinga2-doc-2.12.4-bp152.4.6.1.x86_64", "product_id": "icinga2-doc-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64", "product_id": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64", "product_id": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "nano-icinga2-2.12.4-bp152.4.6.1.x86_64", "product_id": "nano-icinga2-2.12.4-bp152.4.6.1.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-bp152.4.6.1.x86_64", "product": { "name": "vim-icinga2-2.12.4-bp152.4.6.1.x86_64", "product_id": "vim-icinga2-2.12.4-bp152.4.6.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Package Hub 15 SP2", "product": { "name": "SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2" } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "icinga2-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "icinga2-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "icinga2-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "icinga2-bin-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "icinga2-bin-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "icinga2-common-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "icinga2-common-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "icinga2-common-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "icinga2-doc-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "icinga2-doc-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "nano-icinga2-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "nano-icinga2-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp152.4.6.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.aarch64" }, "product_reference": "vim-icinga2-2.12.4-bp152.4.6.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp152.4.6.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.4-bp152.4.6.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-bp152.4.6.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.x86_64" }, "product_reference": "vim-icinga2-2.12.4-bp152.4.6.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.4-bp152.4.6.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.4-bp152.4.6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-19T10:06:13Z", "details": "moderate" } ], "title": "CVE-2020-29663" } ] }
opensuse-su-2021:1089-1
Vulnerability from csaf_opensuse
Published
2021-07-24 18:06
Modified
2021-07-24 18:06
Summary
Security update for icinga2
Notes
Title of the patch
Security update for icinga2
Description of the patch
This update for icinga2 fixes the following issues:
icinga2 was updated to 2.12.5:
Version 2.12.5 fixes two security vulnerabilities that may lead
to privilege escalation for authenticated API users.
Other improvements include several bugfixes related to downtimes,
downtime notifications, and more reliable connection handling.
* Security
- Don't expose the PKI ticket salt via the API. This may lead
to privilege escalation for authenticated API users by them
being able to request certificates for other identities
(CVE-2021-32739)
- Don't expose IdoMysqlConnection, IdoPgsqlConnection, and
ElasticsearchWriter passwords via the API
(CVE-2021-32743)
Depending on your setup, manual intervention beyond installing
the new versions may be required, so please read the more
detailed information in the release blog post carefully.
* Bugfixes
- Don't send downtime end notification if downtime hasn't
started #8878
- Don't let a failed downtime creation block the others #8871
- Support downtimes and comments for checkables with long names
#8870
- Trigger fixed downtimes immediately if the current time
matches (instead of waiting for the timer) #8891
- Add configurable timeout for full connection handshake #8872
* Enhancements
- Replace existing downtimes on ScheduledDowntime change #8880
- Improve crashlog #8869
Patchnames
openSUSE-2021-1089
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for icinga2", "title": "Title of the patch" }, { "category": "description", "text": "This update for icinga2 fixes the following issues:\n\nicinga2 was updated to 2.12.5:\n\n Version 2.12.5 fixes two security vulnerabilities that may lead\n to privilege escalation for authenticated API users.\n Other improvements include several bugfixes related to downtimes,\n downtime notifications, and more reliable connection handling.\n\n * Security\n\n - Don\u0027t expose the PKI ticket salt via the API. This may lead\n to privilege escalation for authenticated API users by them\n being able to request certificates for other identities\n (CVE-2021-32739)\n\n - Don\u0027t expose IdoMysqlConnection, IdoPgsqlConnection, and\n ElasticsearchWriter passwords via the API\n (CVE-2021-32743)\n\n Depending on your setup, manual intervention beyond installing\n the new versions may be required, so please read the more\n detailed information in the release blog post carefully.\n\n * Bugfixes\n\n - Don\u0027t send downtime end notification if downtime hasn\u0027t\n started #8878\n - Don\u0027t let a failed downtime creation block the others #8871\n - Support downtimes and comments for checkables with long names\n #8870\n - Trigger fixed downtimes immediately if the current time\n matches (instead of waiting for the timer) #8891\n - Add configurable timeout for full connection handshake #8872\n * Enhancements\n - Replace existing downtimes on ScheduledDowntime change #8880\n - Improve crashlog #8869\n", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2021-1089", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_1089-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2021:1089-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AG46DROWC4ZEVBNIZC5IYVVFYH4FMFCS/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2021:1089-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AG46DROWC4ZEVBNIZC5IYVVFYH4FMFCS/" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-32739 page", "url": "https://www.suse.com/security/cve/CVE-2021-32739/" }, { "category": "self", "summary": "SUSE CVE CVE-2021-32743 page", "url": "https://www.suse.com/security/cve/CVE-2021-32743/" } ], "title": "Security update for icinga2", "tracking": { "current_release_date": "2021-07-24T18:06:03Z", "generator": { "date": "2021-07-24T18:06:03Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2021:1089-1", "initial_release_date": "2021-07-24T18:06:03Z", "revision_history": [ { "date": "2021-07-24T18:06:03Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "icinga2-2.12.5-bp153.2.5.1.aarch64", "product_id": "icinga2-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "product_id": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "product_id": "icinga2-common-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "product_id": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "product_id": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "product_id": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "product_id": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "product": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "product_id": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64" } } ], "category": "architecture", "name": "aarch64" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "product_id": "icinga2-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "product_id": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "product_id": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "product_id": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "product_id": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "product_id": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "product_id": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le" } }, { "category": "product_version", "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "product": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "product_id": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le" } } ], "category": "architecture", "name": "ppc64le" }, { "branches": [ { "category": "product_version", "name": "icinga2-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "icinga2-2.12.5-bp153.2.5.1.x86_64", "product_id": "icinga2-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "product_id": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "product_id": "icinga2-common-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "product_id": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "product_id": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "product_id": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "product_id": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "product": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "product_id": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "SUSE Package Hub 15 SP1", "product": { "name": "SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1" } }, { "category": "product_name", "name": "SUSE Package Hub 15 SP2", "product": { "name": "SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2" } }, { "category": "product_name", "name": "SUSE Package Hub 15 SP3", "product": { "name": "SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3" } }, { "category": "product_name", "name": "openSUSE Leap 15.2", "product": { "name": "openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.2" } } }, { "category": "product_name", "name": "openSUSE Leap 15.3", "product": { "name": "openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.3" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP1", "product_id": "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP1" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP2", "product_id": "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of SUSE Package Hub 15 SP3", "product_id": "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "SUSE Package Hub 15 SP3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-common-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "relates_to_product_reference": "openSUSE Leap 15.3" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64 as component of openSUSE Leap 15.3", "product_id": "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" }, "product_reference": "vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.3" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-24T18:06:03Z", "details": "moderate" } ], "title": "CVE-2020-29663" }, { "cve": "CVE-2021-32739", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-32739" } ], "notes": [ { "category": "general", "text": "Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user\u0027s credentials, an attacker can view most attributes of all config objects including `ticket_salt` of `ApiListener`. This salt is enough to compute a ticket for every possible common name (CN). A ticket, the master node\u0027s certificate, and a self-signed certificate are enough to successfully request the desired certificate from Icinga. That certificate may in turn be used to steal an endpoint or API user\u0027s identity. Versions 2.12.5 and 2.11.10 both contain a fix the vulnerability. As a workaround, one may either specify queryable types explicitly or filter out ApiListener objects.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-32739", "url": "https://www.suse.com/security/cve/CVE-2021-32739" }, { "category": "external", "summary": "SUSE Bug 1188372 for CVE-2021-32739", "url": "https://bugzilla.suse.com/1188372" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-24T18:06:03Z", "details": "moderate" } ], "title": "CVE-2021-32739" }, { "cve": "CVE-2021-32743", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2021-32743" } ], "notes": [ { "category": "general", "text": "Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions for the corresponding object types. IdoMysqlConnection and IdoPgsqlConnection (every released version) exposes the password of the user used to connect to the database. IcingaDB (added in 2.12.0) exposes the password used to connect to the Redis server. ElasticsearchWriter (added in 2.8.0)exposes the password used to connect to the Elasticsearch server. An attacker who obtains these credentials can impersonate Icinga to these services and add, modify and delete information there. If credentials with more permissions are in use, this increases the impact accordingly. Starting with the 2.11.10 and 2.12.5 releases, these passwords are no longer exposed via the API. As a workaround, API user permissions can be restricted to not allow querying of any affected objects, either by explicitly listing only the required object types for object query permissions, or by applying a filter rule.", "title": "CVE description" } ], "product_status": { "recommended": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2021-32743", "url": "https://www.suse.com/security/cve/CVE-2021-32743" }, { "category": "external", "summary": "SUSE Bug 1188370 for CVE-2021-32743", "url": "https://bugzilla.suse.com/1188370" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 8.8, "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "version": "3.1" }, "products": [ "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1.x86_64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.aarch64", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.ppc64le", "openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-24T18:06:03Z", "details": "moderate" } ], "title": "CVE-2021-32743" } ] }
opensuse-su-2021:1029-1
Vulnerability from csaf_opensuse
Published
2021-07-12 04:06
Modified
2021-07-12 04:06
Summary
Security update for icinga2
Notes
Title of the patch
Security update for icinga2
Description of the patch
This update for icinga2 fixes the following issues:
icinga2 was updated to 2.12.4
* Bugfixes
- Fix a crash when notification objects are deleted using the
API #8782
- Fix crashes that might occur during downtime scheduling if
host or downtime objects are deleted using the API #8785
- Fix an issue where notifications may incorrectly be skipped
after a downtime ends #8775
- Don't send reminder notification if the notification is still
suppressed by a time period #8808
- Fix an issue where attempting to create a duplicate object
using the API might result in the original object being
deleted #8787
- IDO: prioritize program status updates #8809
- Improve exceptions handling, including a fix for an uncaught
exception on Windows #8777
- Retry file rename operations on Windows to avoid intermittent
locking issues #8771
- Update to 2.12.3
* Security
- Fix that revoked certificates due for renewal will
automatically be renewed ignoring the CRL
(Advisory / CVE-2020-29663 - fixes boo#1180147 )
* Bugfixes
- Improve config sync locking - resolves high load issues on
Windows #8511
- Fix runtime config updates being ignored for objects without
zone #8549
- Use proper buffer size for OpenSSL error messages #8542
* Enhancements
- On checkable recovery: re-check children that have a problem
#8506
- Update to 2.12.2
* Bugfixes
- Fix a connection leak with misconfigured agents #8483
- Properly sync changes of config objects in global zones done
via the API #8474 #8470
- Prevent other clients from being disconnected when replaying
the cluster log takes very long #8496
- Avoid duplicate connections between endpoints #8465
- Ignore incoming config object updates for unknown zones #8461
- Check timestamps before removing files in config sync #8495
* Enhancements
- Include HTTP status codes in log #8467
Patchnames
openSUSE-2021-1029
Terms of use
CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).
{ "document": { "aggregate_severity": { "namespace": "https://www.suse.com/support/security/rating/", "text": "moderate" }, "category": "csaf_security_advisory", "csaf_version": "2.0", "distribution": { "text": "Copyright 2024 SUSE LLC. All rights reserved.", "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "en", "notes": [ { "category": "summary", "text": "Security update for icinga2", "title": "Title of the patch" }, { "category": "description", "text": "This update for icinga2 fixes the following issues:\n\nicinga2 was updated to 2.12.4\n\n * Bugfixes\n\n - Fix a crash when notification objects are deleted using the\n API #8782\n - Fix crashes that might occur during downtime scheduling if\n host or downtime objects are deleted using the API #8785\n - Fix an issue where notifications may incorrectly be skipped\n after a downtime ends #8775\n - Don\u0027t send reminder notification if the notification is still\n suppressed by a time period #8808\n - Fix an issue where attempting to create a duplicate object\n using the API might result in the original object being\n deleted #8787\n - IDO: prioritize program status updates #8809\n - Improve exceptions handling, including a fix for an uncaught\n exception on Windows #8777\n - Retry file rename operations on Windows to avoid intermittent\n locking issues #8771\n\n- Update to 2.12.3\n\n * Security\n\n - Fix that revoked certificates due for renewal will \n automatically be renewed ignoring the CRL \n (Advisory / CVE-2020-29663 - fixes boo#1180147 )\n\n * Bugfixes\n\n - Improve config sync locking - resolves high load issues on\n Windows #8511\n - Fix runtime config updates being ignored for objects without\n zone #8549\n - Use proper buffer size for OpenSSL error messages #8542\n\n * Enhancements\n\n - On checkable recovery: re-check children that have a problem\n #8506\n\n- Update to 2.12.2\n\n * Bugfixes\n\n - Fix a connection leak with misconfigured agents #8483\n - Properly sync changes of config objects in global zones done\n via the API #8474 #8470\n - Prevent other clients from being disconnected when replaying\n the cluster log takes very long #8496\n - Avoid duplicate connections between endpoints #8465\n - Ignore incoming config object updates for unknown zones #8461\n - Check timestamps before removing files in config sync #8495\n\n * Enhancements\n\n - Include HTTP status codes in log #8467\n\n", "title": "Description of the patch" }, { "category": "details", "text": "openSUSE-2021-1029", "title": "Patchnames" }, { "category": "legal_disclaimer", "text": "CSAF 2.0 data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).", "title": "Terms of use" } ], "publisher": { "category": "vendor", "contact_details": "https://www.suse.com/support/security/contact/", "name": "SUSE Product Security Team", "namespace": "https://www.suse.com/" }, "references": [ { "category": "external", "summary": "SUSE ratings", "url": "https://www.suse.com/support/security/rating/" }, { "category": "self", "summary": "URL of this CSAF notice", "url": "https://ftp.suse.com/pub/projects/security/csaf/opensuse-su-2021_1029-1.json" }, { "category": "self", "summary": "URL for openSUSE-SU-2021:1029-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/F7IVRID4FOA6YK4ZLJ273QAN3OEQFE4J/" }, { "category": "self", "summary": "E-Mail link for openSUSE-SU-2021:1029-1", "url": "https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/F7IVRID4FOA6YK4ZLJ273QAN3OEQFE4J/" }, { "category": "self", "summary": "SUSE Bug 1180147", "url": "https://bugzilla.suse.com/1180147" }, { "category": "self", "summary": "SUSE CVE CVE-2020-29663 page", "url": "https://www.suse.com/security/cve/CVE-2020-29663/" } ], "title": "Security update for icinga2", "tracking": { "current_release_date": "2021-07-12T04:06:19Z", "generator": { "date": "2021-07-12T04:06:19Z", "engine": { "name": "cve-database.git:bin/generate-csaf.pl", "version": "1" } }, "id": "openSUSE-SU-2021:1029-1", "initial_release_date": "2021-07-12T04:06:19Z", "revision_history": [ { "date": "2021-07-12T04:06:19Z", "number": "1", "summary": "Current version" } ], "status": "final", "version": "1" } }, "product_tree": { "branches": [ { "branches": [ { "branches": [ { "category": "product_version", "name": "icinga2-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "icinga2-2.12.4-lp152.3.6.1.x86_64", "product_id": "icinga2-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-bin-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "icinga2-bin-2.12.4-lp152.3.6.1.x86_64", "product_id": "icinga2-bin-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-common-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "icinga2-common-2.12.4-lp152.3.6.1.x86_64", "product_id": "icinga2-common-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-doc-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "icinga2-doc-2.12.4-lp152.3.6.1.x86_64", "product_id": "icinga2-doc-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64", "product_id": "icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64", "product_id": "icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "nano-icinga2-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "nano-icinga2-2.12.4-lp152.3.6.1.x86_64", "product_id": "nano-icinga2-2.12.4-lp152.3.6.1.x86_64" } }, { "category": "product_version", "name": "vim-icinga2-2.12.4-lp152.3.6.1.x86_64", "product": { "name": "vim-icinga2-2.12.4-lp152.3.6.1.x86_64", "product_id": "vim-icinga2-2.12.4-lp152.3.6.1.x86_64" } } ], "category": "architecture", "name": "x86_64" }, { "branches": [ { "category": "product_name", "name": "openSUSE Leap 15.2", "product": { "name": "openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2", "product_identification_helper": { "cpe": "cpe:/o:opensuse:leap:15.2" } } } ], "category": "product_family", "name": "SUSE Linux Enterprise" } ], "category": "vendor", "name": "SUSE" } ], "relationships": [ { "category": "default_component_of", "full_product_name": { "name": "icinga2-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "icinga2-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-bin-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-bin-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "icinga2-bin-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-common-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-common-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "icinga2-common-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-doc-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-doc-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "icinga2-doc-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "nano-icinga2-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:nano-icinga2-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "nano-icinga2-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" }, { "category": "default_component_of", "full_product_name": { "name": "vim-icinga2-2.12.4-lp152.3.6.1.x86_64 as component of openSUSE Leap 15.2", "product_id": "openSUSE Leap 15.2:vim-icinga2-2.12.4-lp152.3.6.1.x86_64" }, "product_reference": "vim-icinga2-2.12.4-lp152.3.6.1.x86_64", "relates_to_product_reference": "openSUSE Leap 15.2" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-29663", "ids": [ { "system_name": "SUSE CVE Page", "text": "https://www.suse.com/security/cve/CVE-2020-29663" } ], "notes": [ { "category": "general", "text": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "title": "CVE description" } ], "product_status": { "recommended": [ "openSUSE Leap 15.2:icinga2-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.4-lp152.3.6.1.x86_64" ] }, "references": [ { "category": "external", "summary": "CVE-2020-29663", "url": "https://www.suse.com/security/cve/CVE-2020-29663" }, { "category": "external", "summary": "SUSE Bug 1180147 for CVE-2020-29663", "url": "https://bugzilla.suse.com/1180147" } ], "remediations": [ { "category": "vendor_fix", "details": "To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or \"zypper patch\".\n", "product_ids": [ "openSUSE Leap 15.2:icinga2-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.4-lp152.3.6.1.x86_64" ] } ], "scores": [ { "cvss_v3": { "baseScore": 5.3, "baseSeverity": "MEDIUM", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N", "version": "3.1" }, "products": [ "openSUSE Leap 15.2:icinga2-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-bin-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-common-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-doc-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-mysql-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:nano-icinga2-2.12.4-lp152.3.6.1.x86_64", "openSUSE Leap 15.2:vim-icinga2-2.12.4-lp152.3.6.1.x86_64" ] } ], "threats": [ { "category": "impact", "date": "2021-07-12T04:06:19Z", "details": "moderate" } ], "title": "CVE-2020-29663" } ] }
gsd-2020-29663
Vulnerability from gsd
Modified
2023-12-13 01:22
Details
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
Aliases
Aliases
{ "GSD": { "alias": "CVE-2020-29663", "description": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "id": "GSD-2020-29663", "references": [ "https://www.suse.com/security/cve/CVE-2020-29663.html" ] }, "gsd": { "metadata": { "exploitCode": "unknown", "remediation": "unknown", "reportConfidence": "confirmed", "type": "vulnerability" }, "osvSchema": { "aliases": [ "CVE-2020-29663" ], "details": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.", "id": "GSD-2020-29663", "modified": "2023-12-13T01:22:11.782573Z", "schema_version": "1.4.0" } }, "namespaces": { "cve.org": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2020-29663", "STATE": "PUBLIC" }, "affects": { "vendor": { "vendor_data": [ { "product": { "product_data": [ { "product_name": "n/a", "version": { "version_data": [ { "version_value": "n/a" } ] } } ] }, "vendor_name": "n/a" } ] } }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "eng", "value": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "n/a" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2", "refsource": "MISC", "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" }, { "name": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6", "refsource": "MISC", "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" } ] } }, "nvd.nist.gov": { "configurations": { "CVE_data_version": "4.0", "nodes": [ { "children": [], "cpe_match": [ { "cpe23Uri": "cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*", "cpe_name": [], "versionEndIncluding": "2.11.7", "versionStartIncluding": "2.8.0", "vulnerable": true }, { "cpe23Uri": "cpe:2.3:a:icinga:icinga:2.12.2:*:*:*:*:*:*:*", "cpe_name": [], "vulnerable": true } ], "operator": "OR" } ] }, "cve": { "CVE_data_meta": { "ASSIGNER": "cve@mitre.org", "ID": "CVE-2020-29663" }, "data_format": "MITRE", "data_type": "CVE", "data_version": "4.0", "description": { "description_data": [ { "lang": "en", "value": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "en", "value": "CWE-295" } ] } ] }, "references": { "reference_data": [ { "name": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6", "refsource": "MISC", "tags": [ "Third Party Advisory" ], "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" }, { "name": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2", "refsource": "MISC", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" } ] } }, "impact": { "baseMetricV2": { "acInsufInfo": false, "cvssV2": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 6.4, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 4.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "severity": "MEDIUM", "userInteractionRequired": false }, "baseMetricV3": { "cvssV3": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 9.1, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 5.2 } }, "lastModifiedDate": "2020-12-18T16:10Z", "publishedDate": "2020-12-15T23:15Z" } } }
wid-sec-w-2022-1853
Vulnerability from csaf_certbund
Published
2020-12-17 23:00
Modified
2024-12-08 23:00
Summary
Icinga: Schwachstelle ermöglicht Umgehen von Sicherheitsvorkehrungen
Notes
Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen.
Produktbeschreibung
Icinga ist ein Monitoring System.
Angriff
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Icinga ausnutzen, um Sicherheitsvorkehrungen zu umgehen.
Betroffene Betriebssysteme
- Linux
- UNIX
{ "document": { "aggregate_severity": { "text": "mittel" }, "category": "csaf_base", "csaf_version": "2.0", "distribution": { "tlp": { "label": "WHITE", "url": "https://www.first.org/tlp/" } }, "lang": "de-DE", "notes": [ { "category": "legal_disclaimer", "text": "Das BSI ist als Anbieter f\u00fcr die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch daf\u00fcr verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgf\u00e4ltig im Einzelfall zu pr\u00fcfen." }, { "category": "description", "text": "Icinga ist ein Monitoring System.", "title": "Produktbeschreibung" }, { "category": "summary", "text": "Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Icinga ausnutzen, um Sicherheitsvorkehrungen zu umgehen.", "title": "Angriff" }, { "category": "general", "text": "- Linux\n- UNIX", "title": "Betroffene Betriebssysteme" } ], "publisher": { "category": "other", "contact_details": "csaf-provider@cert-bund.de", "name": "Bundesamt f\u00fcr Sicherheit in der Informationstechnik", "namespace": "https://www.bsi.bund.de" }, "references": [ { "category": "self", "summary": "WID-SEC-W-2022-1853 - CSAF Version", "url": "https://wid.cert-bund.de/.well-known/csaf/white/2020/wid-sec-w-2022-1853.json" }, { "category": "self", "summary": "WID-SEC-2022-1853 - Portal Version", "url": "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2022-1853" }, { "category": "external", "summary": "Github Icinga vom 2020-12-17", "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" }, { "category": "external", "summary": "SUSE Security Update SUSE-SU-2022:3725-1 vom 2022-10-25", "url": "https://lists.suse.com/pipermail/sle-security-updates/2022-October/012665.html" }, { "category": "external", "summary": "Gentoo Linux Security Advisory GLSA-202412-08 vom 2024-12-07", "url": "https://security.gentoo.org/glsa/202412-08" } ], "source_lang": "en-US", "title": "Icinga: Schwachstelle erm\u00f6glicht Umgehen von Sicherheitsvorkehrungen", "tracking": { "current_release_date": "2024-12-08T23:00:00.000+00:00", "generator": { "date": "2024-12-09T09:22:21.027+00:00", "engine": { "name": "BSI-WID", "version": "1.3.10" } }, "id": "WID-SEC-W-2022-1853", "initial_release_date": "2020-12-17T23:00:00.000+00:00", "revision_history": [ { "date": "2020-12-17T23:00:00.000+00:00", "number": "1", "summary": "Initiale Fassung" }, { "date": "2022-10-25T22:00:00.000+00:00", "number": "2", "summary": "Neue Updates von SUSE aufgenommen" }, { "date": "2024-12-08T23:00:00.000+00:00", "number": "3", "summary": "Neue Updates von Gentoo aufgenommen" } ], "status": "final", "version": "3" } }, "product_tree": { "branches": [ { "branches": [ { "category": "product_name", "name": "Gentoo Linux", "product": { "name": "Gentoo Linux", "product_id": "T012167", "product_identification_helper": { "cpe": "cpe:/o:gentoo:linux:-" } } } ], "category": "vendor", "name": "Gentoo" }, { "branches": [ { "branches": [ { "category": "product_version_range", "name": "\u003c2.11.8", "product": { "name": "Open Source Icinga \u003c2.11.8", "product_id": "T017934" } }, { "category": "product_version", "name": "2.11.8", "product": { "name": "Open Source Icinga 2.11.8", "product_id": "T017934-fixed", "product_identification_helper": { "cpe": "cpe:/a:icinga:icinga:2.11.8" } } }, { "category": "product_version_range", "name": "\u003c2.12.3", "product": { "name": "Open Source Icinga \u003c2.12.3", "product_id": "T017935" } }, { "category": "product_version", "name": "2.12.3", "product": { "name": "Open Source Icinga 2.12.3", "product_id": "T017935-fixed", "product_identification_helper": { "cpe": "cpe:/a:icinga:icinga:2.12.3" } } } ], "category": "product_name", "name": "Icinga" } ], "category": "vendor", "name": "Open Source" }, { "branches": [ { "category": "product_name", "name": "SUSE Linux", "product": { "name": "SUSE Linux", "product_id": "T002207", "product_identification_helper": { "cpe": "cpe:/o:suse:suse_linux:-" } } } ], "category": "vendor", "name": "SUSE" } ] }, "vulnerabilities": [ { "cve": "CVE-2020-29663", "notes": [ { "category": "description", "text": "Es existiert eine Schwachstelle in Icinga. Widerrufene Zertifikate, die zur Erneuerung anstehen, werden automatisch erneuert wobei die CRL ignoriert wird. Ein Angreifer kann diese Schwachstelle ausnutzen, um Sicherheitsvorkehrungen zu umgehen." } ], "product_status": { "known_affected": [ "T002207", "T017934", "T017935", "T012167" ] }, "release_date": "2020-12-17T23:00:00.000+00:00", "title": "CVE-2020-29663" } ] }
fkie_cve-2020-29663
Vulnerability from fkie_nvd
Published
2020-12-15 23:15
Modified
2024-11-21 05:24
Severity ?
Summary
Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.
References
▶ | URL | Tags | |
---|---|---|---|
cve@mitre.org | https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2 | Patch, Third Party Advisory | |
cve@mitre.org | https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6 | Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2 | Patch, Third Party Advisory | |
af854a3a-2127-422b-91ae-364da2661108 | https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6 | Third Party Advisory |
{ "configurations": [ { "nodes": [ { "cpeMatch": [ { "criteria": "cpe:2.3:a:icinga:icinga:*:*:*:*:*:*:*:*", "matchCriteriaId": "44D41D7C-A345-45EB-8614-6AA652C283FC", "versionEndIncluding": "2.11.7", "versionStartIncluding": "2.8.0", "vulnerable": true }, { "criteria": "cpe:2.3:a:icinga:icinga:2.12.2:*:*:*:*:*:*:*", "matchCriteriaId": "741BA635-D264-457A-8B20-01D19EDD612C", "vulnerable": true } ], "negate": false, "operator": "OR" } ] } ], "cveTags": [], "descriptions": [ { "lang": "en", "value": "Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3." }, { "lang": "es", "value": "Icinga versiones 2 v2.8.0 hasta v2.11.7 y versi\u00f3n v2.12.2, presenta un problema en donde los certificados revocados que deben renovarse ser\u00e1n renovados autom\u00e1ticamente, ignorando la CRL.\u0026#xa0;Este problema es corregido en Icinga versiones 2 v2.11.8 y v2.12.3" } ], "id": "CVE-2020-29663", "lastModified": "2024-11-21T05:24:23.457", "metrics": { "cvssMetricV2": [ { "acInsufInfo": false, "baseSeverity": "MEDIUM", "cvssData": { "accessComplexity": "LOW", "accessVector": "NETWORK", "authentication": "NONE", "availabilityImpact": "NONE", "baseScore": 6.4, "confidentialityImpact": "PARTIAL", "integrityImpact": "PARTIAL", "vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:N", "version": "2.0" }, "exploitabilityScore": 10.0, "impactScore": 4.9, "obtainAllPrivilege": false, "obtainOtherPrivilege": false, "obtainUserPrivilege": false, "source": "nvd@nist.gov", "type": "Primary", "userInteractionRequired": false } ], "cvssMetricV31": [ { "cvssData": { "attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "NONE", "baseScore": 9.1, "baseSeverity": "CRITICAL", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "privilegesRequired": "NONE", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "version": "3.1" }, "exploitabilityScore": 3.9, "impactScore": 5.2, "source": "nvd@nist.gov", "type": "Primary" } ] }, "published": "2020-12-15T23:15:12.780", "references": [ { "source": "cve@mitre.org", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" }, { "source": "cve@mitre.org", "tags": [ "Third Party Advisory" ], "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Patch", "Third Party Advisory" ], "url": "https://github.com/Icinga/icinga2/compare/v2.12.1...v2.12.2" }, { "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Third Party Advisory" ], "url": "https://github.com/Icinga/icinga2/security/advisories/GHSA-pcmr-2p2f-r7j6" } ], "sourceIdentifier": "cve@mitre.org", "vulnStatus": "Modified", "weaknesses": [ { "description": [ { "lang": "en", "value": "CWE-295" } ], "source": "nvd@nist.gov", "type": "Primary" } ] }
Loading…
Loading…
Sightings
Author | Source | Type | Date |
---|
Nomenclature
- Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
- Confirmed: The vulnerability is confirmed from an analyst perspective.
- Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
- Patched: This vulnerability was successfully patched by the user reporting the sighting.
- Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
- Not confirmed: The user expresses doubt about the veracity of the vulnerability.
- Not patched: This vulnerability was not successfully patched by the user reporting the sighting.
Loading…
Loading…