<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for icinga2</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2021:1089-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2021-07-24T18:06:03Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2021-07-24T18:06:03Z</InitialReleaseDate>
    <CurrentReleaseDate>2021-07-24T18:06:03Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for icinga2</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">This update for icinga2 fixes the following issues:

icinga2 was updated to 2.12.5:

  Version 2.12.5 fixes two security vulnerabilities that may lead
  to privilege escalation for authenticated API users.
  Other improvements include several bugfixes related to downtimes,
  downtime notifications, and more reliable connection handling.

  * Security

    - Don't expose the PKI ticket salt via the API. This may lead
      to privilege escalation for authenticated API users by them
      being able to request certificates for other identities
      (CVE-2021-32739)

    - Don't expose IdoMysqlConnection, IdoPgsqlConnection, and
      ElasticsearchWriter passwords via the API
      (CVE-2021-32743)

    Depending on your setup, manual intervention beyond installing
    the new versions may be required, so please read the more
    detailed information in the release blog post carefully.

  * Bugfixes

    - Don't send downtime end notification if downtime hasn't
      started #8878
    - Don't let a failed downtime creation block the others #8871
    - Support downtimes and comments for checkables with long names
      #8870
    - Trigger fixed downtimes immediately if the current time
      matches (instead of waiting for the timer) #8891
    - Add configurable timeout for full connection handshake #8872
  * Enhancements
    - Replace existing downtimes on ScheduledDowntime change #8880
    - Improve crashlog #8869
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-2021-1089</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AG46DROWC4ZEVBNIZC5IYVVFYH4FMFCS/</URL>
      <Description>E-Mail link for openSUSE-SU-2021:1089-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2020-29663/</URL>
      <Description>SUSE CVE CVE-2020-29663 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-32739/</URL>
      <Description>SUSE CVE CVE-2021-32739 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-32743/</URL>
      <Description>SUSE CVE CVE-2021-32743 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP1">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP1">
        <FullProductName ProductID="SUSE Package Hub 15 SP1">SUSE Package Hub 15 SP1</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP2">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP2">
        <FullProductName ProductID="SUSE Package Hub 15 SP2">SUSE Package Hub 15 SP2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="SUSE Package Hub 15 SP3">
      <Branch Type="Product Name" Name="SUSE Package Hub 15 SP3">
        <FullProductName ProductID="SUSE Package Hub 15 SP3">SUSE Package Hub 15 SP3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.2">
      <Branch Type="Product Name" Name="openSUSE Leap 15.2">
        <FullProductName ProductID="openSUSE Leap 15.2" CPE="cpe:/o:opensuse:leap:15.2">openSUSE Leap 15.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="icinga2-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="icinga2-2.12.5-bp153.2.5.1">icinga2-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="icinga2-bin-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="icinga2-bin-2.12.5-bp153.2.5.1">icinga2-bin-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="icinga2-common-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="icinga2-common-2.12.5-bp153.2.5.1">icinga2-common-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="icinga2-doc-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="icinga2-doc-2.12.5-bp153.2.5.1">icinga2-doc-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="icinga2-ido-mysql-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="icinga2-ido-mysql-2.12.5-bp153.2.5.1">icinga2-ido-mysql-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="icinga2-ido-pgsql-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="icinga2-ido-pgsql-2.12.5-bp153.2.5.1">icinga2-ido-pgsql-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="nano-icinga2-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="nano-icinga2-2.12.5-bp153.2.5.1">nano-icinga2-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="vim-icinga2-2.12.5-bp153.2.5.1">
      <FullProductName ProductID="vim-icinga2-2.12.5-bp153.2.5.1">vim-icinga2-2.12.5-bp153.2.5.1</FullProductName>
    </Branch>
    <Relationship ProductReference="icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1">icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-bin-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1">icinga2-bin-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-common-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1">icinga2-common-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-doc-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1">icinga2-doc-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-mysql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1">icinga2-ido-mysql-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-pgsql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1">icinga2-ido-pgsql-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="nano-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1">nano-icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="vim-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP1">
      <FullProductName ProductID="SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1">vim-icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP1</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1">icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-bin-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1">icinga2-bin-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-common-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1">icinga2-common-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-doc-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1">icinga2-doc-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-mysql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1">icinga2-ido-mysql-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-pgsql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1">icinga2-ido-pgsql-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="nano-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1">nano-icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="vim-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP2">
      <FullProductName ProductID="SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1">vim-icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1">icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-bin-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1">icinga2-bin-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-common-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1">icinga2-common-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-doc-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1">icinga2-doc-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-mysql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1">icinga2-ido-mysql-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-pgsql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1">icinga2-ido-pgsql-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nano-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1">nano-icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="vim-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="SUSE Package Hub 15 SP3">
      <FullProductName ProductID="SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1">vim-icinga2-2.12.5-bp153.2.5.1 as a component of SUSE Package Hub 15 SP3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1">icinga2-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-bin-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1">icinga2-bin-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-common-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1">icinga2-common-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-doc-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1">icinga2-doc-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-mysql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1">icinga2-ido-mysql-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-pgsql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1">icinga2-ido-pgsql-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="nano-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1">nano-icinga2-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="vim-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.2">
      <FullProductName ProductID="openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1">vim-icinga2-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1">icinga2-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-bin-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1">icinga2-bin-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-common-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1">icinga2-common-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-doc-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1">icinga2-doc-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-mysql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1">icinga2-ido-mysql-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="icinga2-ido-pgsql-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1">icinga2-ido-pgsql-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="nano-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1">nano-icinga2-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="vim-icinga2-2.12.5-bp153.2.5.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1">vim-icinga2-2.12.5-bp153.2.5.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Icinga 2 v2.8.0 through v2.11.7 and v2.12.2 has an issue where revoked certificates due for renewal will automatically be renewed, ignoring the CRL. This issue is fixed in Icinga 2 v2.11.8 and v2.12.3.</Note>
    </Notes>
    <CVE>CVE-2020-29663</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.4</BaseScore>
        <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:N</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AG46DROWC4ZEVBNIZC5IYVVFYH4FMFCS/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2020-29663.html</URL>
        <Description>CVE-2020-29663</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1180147</URL>
        <Description>SUSE Bug 1180147</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. From version 2.4.0 through version 2.12.4, a vulnerability exists that may allow privilege escalation for authenticated API users. With a read-ony user's credentials, an attacker can view most attributes of all config objects including `ticket_salt` of `ApiListener`. This salt is enough to compute a ticket for every possible common name (CN). A ticket, the master node's certificate, and a self-signed certificate are enough to successfully request the desired certificate from Icinga. That certificate may in turn be used to steal an endpoint or API user's identity. Versions 2.12.5 and 2.11.10 both contain a fix the vulnerability. As a workaround, one may either specify queryable types explicitly or filter out ApiListener objects.</Note>
    </Notes>
    <CVE>CVE-2021-32739</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AG46DROWC4ZEVBNIZC5IYVVFYH4FMFCS/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-32739.html</URL>
        <Description>CVE-2021-32739</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1188372</URL>
        <Description>SUSE Bug 1188372</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Icinga is a monitoring system which checks the availability of network resources, notifies users of outages, and generates performance data for reporting. In versions prior to 2.11.10 and from version 2.12.0 through version 2.12.4, some of the Icinga 2 features that require credentials for external services expose those credentials through the API to authenticated API users with read permissions for the corresponding object types. IdoMysqlConnection and IdoPgsqlConnection (every released version) exposes the password of the user used to connect to the database. IcingaDB (added in 2.12.0) exposes the password used to connect to the Redis server. ElasticsearchWriter (added in 2.8.0)exposes the password used to connect to the Elasticsearch server. An attacker who obtains these credentials can impersonate Icinga to these services and add, modify and delete information there. If credentials with more permissions are in use, this increases the impact accordingly. Starting with the 2.11.10 and 2.12.5 releases, these passwords are no longer exposed via the API. As a workaround, API user permissions can be restricted to not allow querying of any affected objects, either by explicitly listing only the required object types for object query permissions, or by applying a filter rule.</Note>
    </Notes>
    <CVE>CVE-2021-32743</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>SUSE Package Hub 15 SP1:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP1:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP2:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>SUSE Package Hub 15 SP3:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.2:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-bin-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-common-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-doc-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-ido-mysql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:icinga2-ido-pgsql-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:nano-icinga2-2.12.5-bp153.2.5.1</ProductID>
        <ProductID>openSUSE Leap 15.3:vim-icinga2-2.12.5-bp153.2.5.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSet>
        <BaseScore>6.5</BaseScore>
        <Vector>AV:N/AC:L/Au:S/C:P/I:P/A:P</Vector>
      </ScoreSet>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/AG46DROWC4ZEVBNIZC5IYVVFYH4FMFCS/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-32743.html</URL>
        <Description>CVE-2021-32743</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1188370</URL>
        <Description>SUSE Bug 1188370</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
