GHSA-4w2r-vx7w-6p4wLowCVSS 3.5
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function...
🔗 CVE IDs covered (1)
📋 Description
An issue was discovered in Nagios XI before 5.9.3. The is_insecure_login_authenticated function uses a insecure timing comparison that leads to an attacker being able to bruteforce the admin password, by measuring timing differences in the comparison.