CVE-2017-16933: Icinga
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
etc/initsystem/prepare-dirs in Icinga 2.x through 2.8.1 has a chown call for a filename in a user-writable directory, which allows local users to gain privileges by leveraging access to the $ICINGA2_USER account for creation of a link.
Affected products
- Icinga Icinga: from 2.0.0, up to and including 2.8.0
Published 2017-11-24. Last modified 2026-06-17.