VDB
Sign up
HIGH8.5

GHSA-c4fj-3wqq-g9c9

Centreon Command Injection

Quick fix

GHSA-c4fj-3wqq-g9c9 — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^2.8.28

Details

The `escape_command` function in `include/Administration/corePerformance/getStats.php` in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (offending file deleted in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the `ns_id` parameter.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 0Fixed in: 2.8.28
Fixcomposer require centreon/centreon:^2.8.28

References