VDB
Sign up
HIGH8.8

GHSA-2q95-593f-g7h7

OS Command Injection in Centreon

Quick fix

GHSA-2q95-593f-g7h7 — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^20.04.0

Details

/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 0Fixed in: 20.04.0
Fixcomposer require centreon/centreon:^20.04.0

References