Candidate: CVE-2018-18250 PublicDate: 2018-12-17 15:29:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-18250 https://herolab.usd.de/wp-content/uploads/sites/4/2018/12/usd20180030.txt Description: Icinga Web 2 before 2.6.2 allows parameters that break navigation dashlets, as demonstrated by a single '$' character as the Name of a Navigation item. Ubuntu-Description: Notes: Bugs: Priority: medium Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N [7.5 HIGH] Patches_icingaweb2: upstream_icingaweb2: needs-triage precise/esm_icingaweb2: DNE trusty_icingaweb2: DNE trusty/esm_icingaweb2: DNE xenial_icingaweb2: ignored (end of standard support, was needs-triage) bionic_icingaweb2: needs-triage cosmic_icingaweb2: ignored (reached end-of-life) disco_icingaweb2: not-affected (2.6.2-2) eoan_icingaweb2: ignored (reached end-of-life) focal_icingaweb2: needs-triage groovy_icingaweb2: ignored (reached end-of-life) hirsute_icingaweb2: ignored (reached end-of-life) impish_icingaweb2: needs-triage jammy_icingaweb2: needs-triage devel_icingaweb2: needs-triage