First published: Mon Jun 25 2018(Updated: )
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/centreon/centreon | =2.8.23 | 2.8.24 |
composer/centreon/centreon | =3.4.6 | |
Centreon Centreon | =3.4.6 | |
Centreon Centreon Web | =2.8.23 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-11587 is a vulnerability that allows remote code execution in Centreon 3.4.6 and Centreon Web 2.8.23.
CVE-2018-11587 has a severity rating of 9.8, which is considered critical.
Centreon 3.4.6 and Centreon Web 2.8.23 are affected by CVE-2018-11587.
To fix CVE-2018-11587, update to Centreon Web 2.8.24 or Centreon 3.4.6.
You can find more information about CVE-2018-11587 at the following references: - [NVD](https://nvd.nist.gov/vuln/detail/CVE-2018-11587) - [Centreon Release Notes](https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html) - [GitHub Pull Request](https://github.com/centreon/centreon-archived/pull/6263)