CVE-2020-9463: OS Command Injection
Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the serverip field in JSON data in an api/internal.php?object=centreonconfigurationremote request.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for Centreon 19.10?
The vulnerability ID for Centreon 19.10 is CVE-2020-9463.
What is the severity of CVE-2020-9463?
The severity of CVE-2020-9463 is critical with a CVSS score of 8.8.
How does Centreon 19.10 allow remote authenticated users to execute arbitrary OS commands?
Centreon 19.10 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the server_ip field in JSON data in an api/internal.php?object=centreon_configuration_remote request.
What is the affected software version for CVE-2020-9463?
The affected software version for CVE-2020-9463 is Centreon 19.10.
Is there a fix available for CVE-2020-9463?
There is currently no known fix available for CVE-2020-9463. It is recommended to update to a newer version of Centreon when a fix becomes available.