CVE-2019-17107: OS Command Injection
Published Oct 8, 2019
·Updated
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the commandhostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.
Affected Software
2 affected components
Centreon Centreon Web>=2.8<2.8.27
Centreon Centreon Web>=18.10.0<18.10.4
Remediation
Patch Available
Patch Available
Patch Available
Event History
Oct 8, 2019
CVE Published
via MITRE·12:24 PM
Data Sourced
via MITRE·12:24 PM
Description
Frequently Asked Questions
1
What is CVE-2019-17107?
CVE-2019-17107 is a vulnerability in Centreon Web before version 2.8.27 that allows authenticated attackers to execute arbitrary code.
2
How can an attacker exploit CVE-2019-17107?
Authenticated attackers can exploit CVE-2019-17107 by using the command_hostaddress parameter in the minPlayCommand.php file.
3
What is the severity of CVE-2019-17107?
CVE-2019-17107 has a severity rating of 8.8 (High).
4
Which software is affected by CVE-2019-17107?
Centreon Web versions 2.8.0 to 2.8.26 and 18.10.0 to 18.10.4 are affected by CVE-2019-17107.
5
How can I fix CVE-2019-17107?
To fix CVE-2019-17107, update Centreon Web to version 2.8.27 or later.