CVE-2018-6532Uncontrolled Resource Consumption in Icinga

Severity
7.5HIGHNVD
EPSS
0.7%
top 27.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 27
Latest updateMay 14

Description

An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafted (authenticated and unauthenticated) requests, an attacker can exhaust a lot of memory on the server side, triggering the OOM killer.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

Debianicinga/icinga2< 2.8.4-1+3
NVDicinga/icinga2.0.02.8.0

🔴Vulnerability Details

3
GHSA
GHSA-7vvj-647q-jgx2: An issue was discovered in Icinga 22022-05-14
OSV
CVE-2018-6532: An issue was discovered in Icinga 22018-02-27
CVEList
CVE-2018-6532: An issue was discovered in Icinga 22018-02-27

📋Vendor Advisories

1
Debian
CVE-2018-6532: icinga2 - An issue was discovered in Icinga 2.x through 2.8.1. By sending specially crafte...2018
CVE-2018-6532 — Uncontrolled Resource Consumption | cvebase