VDB
Sign up
MEDIUM5.4

GHSA-r5mf-q76q-f2xq

Cross-site scripting in Centreon

Quick fix

GHSA-r5mf-q76q-f2xq — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^20.10.7

Details

Centreon version 20.10.2 is affected by a cross-site scripting (XSS) vulnerability. The dep_description (Dependency Description) and dep_name (Dependency Name) parameters are vulnerable to stored XSS. A user has to log in and go to the Configuration > Notifications > Hosts page.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 0Fixed in: 20.10.7
Fixcomposer require centreon/centreon:^20.10.7

References