High severity7.8NVD Advisory· Published Jun 12, 2020· Updated Jun 17, 2026
CVE-2020-14004
CVE-2020-14004
Description
An issue was discovered in Icinga2 before v2.12.0-rc1. The prepare-dirs script (run as part of the icinga2 systemd service) executes chmod 2750 /run/icinga2/cmd. /run/icinga2 is under control of an unprivileged user by default. If /run/icinga2/cmd is a symlink, then it will by followed and arbitrary files can be changed to mode 2750 by the unprivileged icinga2 user.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
14cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
- cpe:2.3:a:opensuse:backports_sle:15.0:sp2:*:*:*:*:*:*
- Icinga2/Icinga2description
- osv-coords6 versionspkg:rpm/opensuse/icinga2&distro=openSUSE%20Leap%2015.1pkg:rpm/opensuse/icinga2&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/icinga2&distro=openSUSE%20Tumbleweedpkg:rpm/suse/icinga2&distro=SUSE%20Linux%20Enterprise%20Module%20for%20HPC%2012pkg:rpm/suse/icinga2&distro=SUSE%20Package%20Hub%2015%20SP1pkg:rpm/suse/icinga2&distro=SUSE%20Package%20Hub%2015%20SP2
< 2.12.1-bp152.4.3.1+ 5 more
- (no CPE)range: < 2.12.1-bp152.4.3.1
- (no CPE)range: < 2.12.1-bp152.4.3.1
- (no CPE)range: < 2.13.1-1.3
- (no CPE)range: < 2.8.2-3.6.1
- (no CPE)range: < 2.12.1-bp152.4.3.1
- (no CPE)range: < 2.12.1-bp152.4.3.1
Patches
Vulnerability mechanics
References
6- github.com/Icinga/icinga2/pull/8045/commits/2f0f2e8c355b75fa4407d23f85feea037d2bc4b6nvdPatchThird Party Advisory
- www.openwall.com/lists/oss-security/2020/06/12/1nvdExploitMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2020-11/msg00014.htmlnvdBroken LinkMailing ListThird Party Advisory
- github.com/Icinga/icinga2/compare/v2.12.0-rc1...masternvdThird Party Advisory
- github.com/Icinga/icinga2/releasesnvdRelease NotesThird Party Advisory
- bugzilla.suse.com/show_bug.cginvdBroken LinkIssue Tracking
News mentions
0No linked articles in our index yet.