Icinga 2 JSON-RPC endpoint skips sender validation, allows node injection
Unauthenticated attacker can inject a malicious node into an Icinga 2 cluster by spoofing certificate update JSON-RPC messages. CVSS 9.8 critical. Fixed in 2.14.9, 2.15.4, 2.16.2.
- Vendor
- Icinga
- Product
- Icinga 2
- CVSS
- 9.8
- EPSS (exploit probability)
- 0.4%
- Status
- patched
- Published
Icinga 2’s JSON-RPC message handling for certificate updates does not verify that the sender is a trusted cluster endpoint. From version 2.8 through 2.14.8, 2.15.3, and 2.16.1, an unauthenticated remote attacker can send crafted certificate update messages to force Icinga 2 to accept a malicious node as trusted, compromising cluster integrity.
Fixed in Icinga 2.14.9, 2.15.4, and 2.16.2. No workaround is documented. Upgrade immediately; this is an unauthenticated cluster takeover path.
See NVD and the Icinga 2 GitHub advisory for version details.
