First published: Thu Mar 05 2020(Updated: )
An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Centreon Centreon | >=18.0.0<18.10.8 | |
Centreon Centreon | >=19.04.0<19.04.5 | |
Centreon Centreon | >=19.10.0<19.10.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-17646 is high, with a severity value of 7.5.
CVE-2019-17646 can be exploited by making an unauthenticated direct request to api/external.php?object=centreon_metric&action=listByService to obtain sensitive information.
CVE-2019-17646 affects Centreon versions before 18.10.8, 19.04.5, and 19.10.2.
To fix CVE-2019-17646, upgrade Centreon to version 18.10.8, 19.04.5, or 19.10.2 or later.
You can find more information about CVE-2019-17646 in the Centreon release notes: [link1], [link2], [link3].