PT-2018-17619 · Icinga · Icinga
Crunsher
·
Publicado
2018-02-27
·
Atualizado
2019-10-03
·
CVE-2018-6535
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Icinga versions 2.x through 2.8.1
Description
An issue in the password comparison function can disclose the password to an attacker due to the lack of a constant-time comparison, potentially allowing attackers to exploit this and gain unauthorized access.
Recommendations
For versions 2.x through 2.8.1, update to a version that includes a constant-time password comparison function to prevent password disclosure.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Icinga