PT-2018-17619 · Icinga · Icinga
Crunsher
·
Published
2018-02-27
·
Updated
2019-10-03
·
CVE-2018-6535
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Icinga versions 2.x through 2.8.1
Description
An issue in the password comparison function can disclose the password to an attacker due to the lack of a constant-time comparison, potentially allowing attackers to exploit this and gain unauthorized access.
Recommendations
For versions 2.x through 2.8.1, update to a version that includes a constant-time password comparison function to prevent password disclosure.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Icinga