VDB
Sign up
MEDIUM6.5

GHSA-rx4j-x3fh-9qwg

Centreon Sensitive Data Exposure

Quick fix

GHSA-rx4j-x3fh-9qwg — centreon/centreon: upgrade to the fixed version with the command below.

composer require centreon/centreon:^2.8.30

Details

In Centreon Web through 2.8.29, disclosure of external components' passwords allows authenticated attackers to move laterally to external components.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/centreon/centreon
Introduced in: 0Fixed in: 2.8.30
Fixcomposer require centreon/centreon:^2.8.30

References