VDB
Sign up
MEDIUM4.3

GHSA-h5qv-p378-3hhr

Centreon Sensitive Data Exposure vulnerability

Quick fix

GHSA-h5qv-p378-3hhr — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^19.10.7

Details

Centreon before 19.10.7 exposes Session IDs in server responses.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 19.10.0Fixed in: 19.10.7
Fixcomposer require centreon/centreon:^19.10.7
Packagist/centreon/centreon
Introduced in: 19.0.0Fixed in: 19.04.10
Fixcomposer require centreon/centreon:^19.04.10
Packagist/centreon/centreon
Introduced in: 18.0.0Fixed in: 18.10.11
Fixcomposer require centreon/centreon:^18.10.11
Packagist/centreon/centreon
Introduced in: 0Fixed in: 2.8.32
Fixcomposer require centreon/centreon:^2.8.32

References