PT-2020-9935 · Centreon · Centreon
Published
2020-03-04
·
Updated
2021-07-21
·
CVE-2019-17644
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Centreon versions prior to 2.8-30
Centreon versions prior to 18.10-8
Centreon versions prior to 19.04-5
Centreon versions prior to 19.10-2
Description
The issue provides sensitive information via an unauthenticated direct request for "include/configuration/configObject/host/refreshMacroAjax.php".
Recommendations
For Centreon versions prior to 2.8-30, update to version 2.8-30 or later.
For Centreon versions prior to 18.10-8, update to version 18.10-8 or later.
For Centreon versions prior to 19.04-5, update to version 19.04-5 or later.
For Centreon versions prior to 19.10-2, update to version 19.10-2 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Centreon