CRITICAL9.8
GHSA-c8qc-cp8v-prpx
Centreon RCE Vulnerability
Quick fix
GHSA-c8qc-cp8v-prpx — centreon/centreon: upgrade to the fixed version with the command below.
composer require centreon/centreon:^2.8.24Details
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
No fixed version published yet for centreon/centreon (composer). Pin to a known-safe version or switch to an alternative.
Packagist/centreon/centreon
Introduced in:
2.8.23Fixed in: 2.8.24Fix
composer require centreon/centreon:^2.8.24References
- https://nvd.nist.gov/vuln/detail/CVE-2018-11587[ADVISORY]
- https://github.com/centreon/centreon-archived/pull/6263[WEB]
- https://github.com/centreon/centreon-archived/pull/6263/commits/fb438e6aaf133cc5f9d25130653ba8fdc6ecf51f[WEB]
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html[WEB]