Unauthorized File Permission Changes in Icinga2 by Icinga
CVE-2020-14004
7.8HIGH
What is CVE-2020-14004?
A vulnerability in Icinga2 allows an unprivileged user to manipulate file permissions within the /run/icinga2/cmd directory. The prepare-dirs script, run as part of the icinga2 systemd service, executes a command that can change permission settings of arbitrary files to 2750 if /run/icinga2/cmd is a symlink. This leads to unauthorized access and potential exploitation by altering file attributes, posing risks to system integrity.
