vendor:
Fail2ban
by:
7.5
CVSS
HIGH
Remote Denial-of-Service
CWE
Product Name: Fail2ban
Affected Version From: Fail2ban 0.8.0
Affected Version To: Fail2ban 0.8.0
Patch Exists: YES
Related CWE:
CPE: cpe:2.3:a:fail2ban_project:fail2ban:0.8.0:*:*:*:*:*:*:*
Platforms Tested:
Remote Denial-of-Service Vulnerability in Fail2ban
The vulnerability in Fail2ban allows remote attackers to add arbitrary IP addresses to the block list used by the application, denying service to legitimate users.
Mitigation:
Upgrade to Fail2ban version 0.8.1 or later.