HIGH7.2
GHSA-4f26-v6fr-9hmp
Improper Input Validation in Centreon Web
Quick fix
GHSA-4f26-v6fr-9hmp — centreon/centreon: upgrade to the fixed version with the command below.
composer require centreon/centreon:^18.10.8Details
Centreon Web 19.04.4 allows Remote Code Execution by an administrator who can modify Macro Expression location settings.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
Introduced in:
0Fixed in: 18.10.8Fix
composer require centreon/centreon:^18.10.8Packagist/centreon/centreon
Introduced in:
19.0.0Fixed in: 19.04.5Fix
composer require centreon/centreon:^19.04.5References
- https://nvd.nist.gov/vuln/detail/CVE-2019-16405[ADVISORY]
- https://github.com/centreon/centreon/pull/7864[WEB]
- https://github.com/centreon/centreon/pull/7884[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10.html[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10.html[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8.html[WEB]
- https://github.com/TheCyberGeek/CVE-2019-16405.rb[WEB]
- https://github.com/centreon/centreon[PACKAGE]
- https://github.com/centreon/centreon/releases/tag/19.04.5[WEB]
- https://thecybergeek.co.uk/cves/2019/09/17/CVE-2019-16405-06.html[WEB]
- https://thecybergeek.co.uk/cves/2019/09/19/CVEs.html[WEB]
- http://packetstormsecurity.com/files/155999/Centreon-19.04-Remote-Code-Execution.html[WEB]