CVE-2018-6535: High severity Icinga Icinga vulnerability
Published Feb 27, 2018
·Updated
An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.
Affected Software
1 affected component
Icinga Icinga>=2.0.0<=2.8.1
Event History
Feb 27, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Data Sourced
via NVD·07:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is CVE-2018-6535?
CVE-2018-6535 is a vulnerability in Icinga 2.x through 2.8.1 that can disclose the password to an attacker.
2
What software versions are affected by CVE-2018-6535?
CVE-2018-6535 affects Icinga 2.x versions between 2.0.0 and 2.8.1.
3
How severe is CVE-2018-6535?
CVE-2018-6535 has a severity rating of 8.1 (High).
4
How can I fix CVE-2018-6535?
To fix CVE-2018-6535, you should update your Icinga 2.x installation to a version higher than 2.8.1.
5
Where can I find more information about CVE-2018-6535?
You can find more information about CVE-2018-6535 in the following references: [GitHub Issue #4920](https://github.com/Icinga/icinga2/issues/4920) and [GitHub Pull Request #5715](https://github.com/Icinga/icinga2/pull/5715).