CVE-2019-17646: High severity centreon vulnerability
Published Mar 5, 2020
·Updated
An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreonmetric&action=listByService.
Affected Software
3 affected components
Centreon Centreon>=18.0.0<18.10.8
Centreon Centreon>=19.04.0<19.04.5
Centreon Centreon>=19.10.0<19.10.2
Remediation
Patch Available
Event History
Mar 5, 2020
CVE Published
via MITRE·07:49 PM
Data Sourced
via MITRE·07:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-17646?
The severity of CVE-2019-17646 is high, with a severity value of 7.5.
2
How can I exploit CVE-2019-17646?
CVE-2019-17646 can be exploited by making an unauthenticated direct request to api/external.php?object=centreon_metric&action=listByService to obtain sensitive information.
3
Which versions of Centreon are affected by CVE-2019-17646?
CVE-2019-17646 affects Centreon versions before 18.10.8, 19.04.5, and 19.10.2.
4
How do I fix CVE-2019-17646?
To fix CVE-2019-17646, upgrade Centreon to version 18.10.8, 19.04.5, or 19.10.2 or later.
5
Where can I find more information about CVE-2019-17646?
You can find more information about CVE-2019-17646 in the Centreon release notes: [link1], [link2], [link3].