Authentication Bypass Affecting centreon/centreon package, versions <19.10.7


0.0
low

Snyk CVSS

    Attack Complexity Low
    User Interaction Required
    Scope Changed

    Threat Intelligence

    EPSS 0.06% (24th percentile)
Expand this section
NVD
4.3 medium

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk ID SNYK-PHP-CENTREONCENTREON-570527
  • published 28 May 2020
  • disclosed 28 May 2020
  • credit Jean-Baptiste 'ajabep' Parmentier

How to fix?

Upgrade centreon/centreon to version 19.10.7 or higher.

Overview

centreon/centreon is a network, system, applicative supervision and monitoring tool.

Affected versions of this package are vulnerable to Authentication Bypass. User session IDs are exposed in some of the server's HTTP responses.

References