First published: Wed Jul 03 2019(Updated: )
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
DNN (DotNetNuke) | >=9.2<=9.2.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-18326 is a vulnerability in DNN (aka DotNetNuke) versions 9.2 through 9.2.2 that results in lower than expected entropy due to incorrect conversion of encryption key source values.
CVE-2018-18326 lowers the expected entropy in DNN (DotNetNuke) 9.2 - 9.2.2, which can weaken the security of encryption.
CVE-2018-18326 has a severity rating of 7.5 (high).
The Common Weakness Enumeration (CWE) ID for CVE-2018-18326 is 331.
To fix CVE-2018-18326, users should upgrade their DNN (DotNetNuke) installations to version 9.2.3 or later.