CVE-2021-28055: CSRF
An issue was discovered in Centreon-Web in Centreon Platform 20.10.0. The anti-CSRF token generation is predictable, which might allow CSRF attacks that add an admin user.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-28055?
CVE-2021-28055 is an issue discovered in Centreon-Web in Centreon Platform 20.10.0, where the anti-CSRF token generation is predictable, allowing CSRF attacks to add an admin user.
What is the severity of CVE-2021-28055?
CVE-2021-28055 has a severity level of medium, with a CVSS score of 6.5.
How does CVE-2021-28055 affect Centreon?
CVE-2021-28055 affects Centreon Platform 20.10.0, allowing CSRF attacks to add an admin user.
How can I fix CVE-2021-28055?
To fix CVE-2021-28055, it is recommended to upgrade Centreon Platform to a version that has addressed the predictable anti-CSRF token generation vulnerability.
Where can I find more information about CVE-2021-28055?
More information about CVE-2021-28055 can be found at the following reference: [https://github.com/centreon/centreon/pull/9612](https://github.com/centreon/centreon/pull/9612).