CVE-2019-15299: High severity centreon vulnerability
Published Feb 24, 2020
·Updated
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contactautologinkey field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
Affected Software
1 affected component
Centreon Centreon Web<=19.04.3
Remediation
Patch Available
Event History
Feb 24, 2020
CVE Published
via MITRE·12:55 PM
Data Sourced
via MITRE·12:55 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue in Centreon Web?
The vulnerability ID for this issue in Centreon Web is CVE-2019-15299.
2
What is the severity level of CVE-2019-15299?
The severity level of CVE-2019-15299 is high.
3
What is the affected software version of CVE-2019-15299?
The affected software version of CVE-2019-15299 is Centreon Web up to and including 19.04.3.
4
What is the impact of CVE-2019-15299?
CVE-2019-15299 allows partial bypassing of authentication in Centreon Web.
5
Is there a fix available for CVE-2019-15299?
Yes, you can find the fix for CVE-2019-15299 in Centreon Web release notes (v19.04 and v19.10) and the Centreon GitHub pull request #8072.