HIGH8.8
GHSA-jmgg-wx67-7qfv
Command Injection in Centreon
Quick fix
GHSA-jmgg-wx67-7qfv — centreon/centreon: upgrade to the fixed version with the command below.
composer require centreon/centreon:^19.04.15Details
Centreon before 19.04.15 allows remote attackers to execute arbitrary OS commands by placing shell metacharacters in RRDdatabase_status_path (via a main.get.php request) and then visiting the include/views/graphs/graphStatus/displayServiceStatus.php page.
Are you affected?
Enter the version of the package you're using.
Affected packages
Packagist/centreon/centreon
Introduced in:
0Fixed in: 19.04.15Fix
composer require centreon/centreon:^19.04.15References
- https://nvd.nist.gov/vuln/detail/CVE-2020-13252[ADVISORY]
- https://github.com/centreon/centreon/pull/8467[WEB]
- https://engindemirbilek.github.io/centreon-19.10-rce[WEB]
- https://github.com/EnginDemirbilek/EnginDemirbilek.github.io/blob/master/centreon-19.10-rce.html[WEB]
- https://github.com/centreon/centreon/compare/19.04.13...19.04.15[WEB]