First published: Tue Feb 27 2018(Updated: )
An issue was discovered in Icinga 2.x through 2.8.1. The lack of a constant-time password comparison function can disclose the password to an attacker.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Icinga Icinga | >=2.0.0<=2.8.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-6535 is a vulnerability in Icinga 2.x through 2.8.1 that can disclose the password to an attacker.
CVE-2018-6535 affects Icinga 2.x versions between 2.0.0 and 2.8.1.
CVE-2018-6535 has a severity rating of 8.1 (High).
To fix CVE-2018-6535, you should update your Icinga 2.x installation to a version higher than 2.8.1.
You can find more information about CVE-2018-6535 in the following references: [GitHub Issue #4920](https://github.com/Icinga/icinga2/issues/4920) and [GitHub Pull Request #5715](https://github.com/Icinga/icinga2/pull/5715).