VDB
Sign up
MEDIUM6.5

GHSA-7rg4-266c-jqw6

Predictable CSRF tokens in centreon/centreon

Quick fix

GHSA-7rg4-266c-jqw6 — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^20.10.7

Details

An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 20.10.0Fixed in: 20.10.7
Fixcomposer require centreon/centreon:^20.10.7
Packagist/centreon/centreon
Introduced in: 20.04.0Fixed in: 20.04.13
Fixcomposer require centreon/centreon:^20.04.13
Packagist/centreon/centreon
Introduced in: 19.10.0Fixed in: 19.10.23
Fixcomposer require centreon/centreon:^19.10.23
Packagist/centreon/centreon
Introduced in: 0Fixed in: 2.8.37
Fixcomposer require centreon/centreon:^2.8.37

References