Certificate Renewal Bypass in Icinga 2 by Icinga
CVE-2020-29663
9.1CRITICAL
What is CVE-2020-29663?
Icinga 2 versions v2.8.0 through v2.11.7 and v2.12.2 introduce a vulnerability allowing revoked certificates due for renewal to be automatically renewed, neglecting the Certificate Revocation List (CRL). This poses significant risks as it permits continued trust in certificates that should have been invalidated, potentially leading to unauthorized access or exploitation. This issue is rectified in Icinga 2 v2.11.8 and v2.12.3.
