CVE-2020-22345: OS Command Injection
Published Aug 18, 2021
·Updated
/graphStatus/displayServiceStatus.php in Centreon 19.10.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabasepath parameter.
Affected Software
1 affected component
Centreon Centreon=19.10.8
Remediation
Event History
Aug 18, 2021
CVE Published
via MITRE·08:21 PM
Data Sourced
via MITRE·08:21 PM
Description
Frequently Asked Questions
1
What is CVE-2020-22345?
CVE-2020-22345 is a vulnerability in Centreon 19.10.8 that allows remote attackers to execute arbitrary OS commands via shell metacharacters in the RRDdatabase_path parameter.
2
What is the severity of CVE-2020-22345?
The severity of CVE-2020-22345 is critical with a CVSS score of 8.8.
3
How does CVE-2020-22345 affect Centreon?
CVE-2020-22345 affects Centreon 19.10.8.
4
How can remote attackers exploit CVE-2020-22345?
Remote attackers can exploit CVE-2020-22345 by sending malicious input containing shell metacharacters in the RRDdatabase_path parameter.
5
Is there a fix available for CVE-2020-22345?
Yes, a fix for CVE-2020-22345 is available. Please refer to the provided references for more information.