7.2
CVSSv2

CVE-2018-6533

Published: 27/02/2018 Updated: 03/10/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists in Icinga 2.x up to and including 2.8.1. By editing the init.conf file, Icinga 2 can be run as root. Following this the program can be used to run arbitrary code as root. This was fixed by no longer using init.conf to determine account information for any root-executed code (a larger issue than CVE-2017-16933).

Vulnerable Product Search on Vulmon Subscribe to Product

icinga icinga

Vendor Advisories

Debian Bug report logs - #883247 CVE-2017-16933: icinga2: root privilege escalation via prepare-dirs Package: icinga2; Maintainer for icinga2 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Source for icinga2 is src:icinga2 (PTS, buildd, popcon) Reported by: Henri Salo <henri@nervfi> Da ...
Debian Bug report logs - #897301 CVE-2018-6532 CVE-2018-6534 CVE-2018-6535 Package: src:icinga2; Maintainer for src:icinga2 is Debian Nagios Maintainer Group <pkg-nagios-devel@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Tue, 1 May 2018 10:12:08 UTC Severity: important Tags: secur ...