CVE-2017-16933: Icinga

High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.

etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.

Affected products

  • Icinga Icinga: from 2.0.0, up to and including 2.8.0

Published 2017-11-24. Last modified 2026-06-17.