MEDIUM4.3
GHSA-h5qv-p378-3hhr
Centreon Sensitive Data Exposure vulnerability
Quick fix
GHSA-h5qv-p378-3hhr — centreon/centreon: upgrade to the fixed version with the command below.
composer require centreon/centreon:^19.10.7Details
Centreon before 19.10.7 exposes Session IDs in server responses.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
Introduced in:
19.10.0Fixed in: 19.10.7Fix
composer require centreon/centreon:^19.10.7Packagist/centreon/centreon
Introduced in:
19.0.0Fixed in: 19.04.10Fix
composer require centreon/centreon:^19.04.10Packagist/centreon/centreon
Introduced in:
18.0.0Fixed in: 18.10.11Fix
composer require centreon/centreon:^18.10.11Packagist/centreon/centreon
Introduced in:
0Fixed in: 2.8.32Fix
composer require centreon/centreon:^2.8.32References
- https://nvd.nist.gov/vuln/detail/CVE-2020-10945[ADVISORY]
- https://github.com/centreon/centreon-archived/pull/8291[WEB]
- https://github.com/centreon/centreon-archived/commit/02a3248602ce194fbb098af34be4652565db2468[WEB]
- https://github.com/centreon/centreon-archived/commit/1c14a8ee07225836bdd2ca480e47a63070a11bb9[WEB]
- https://github.com/centreon/centreon-archived/commit/afa0ee6d43d22860ae435163559912696569fc2f[WEB]
- https://github.com/centreon/centreon-archived/commit/fbee38536960eecaf52eda2bf31b90859c018b66[WEB]
- https://github.com/centreon/centreon[PACKAGE]
- https://web.archive.org/web/20200625084841/https://sysdream.com/news/lab/2020-05-13-cve-2020-10945-centreon-session-id-exposure[WEB]