CVE-2025-12519: Information disclosure on Administration parameters API endpoint
Missing Authorization vulnerability in Centreon Infra Monitoring (Administration parameters API endpoint modules) allows Accessing Functionality Not Properly Constrained by ACLs, resulting in Information Disclosure like downtime or acknowledgement configurations. This issue affects Infra Monitoring: from 25.10.0 before 25.10.2, from 24.10.0 before 24.10.15, from 24.04.0 before 24.04.19.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12519?
The severity of CVE-2025-12519 is classified as medium due to the potential for information disclosure through unauthorized access.
How do I fix CVE-2025-12519?
To fix CVE-2025-12519, update Centreon Infra Monitoring to the latest version that addresses the missing authorization issue.
Who is affected by CVE-2025-12519?
CVE-2025-12519 affects users of Centreon Infra Monitoring versions between 24.04.0 to 24.04.19, 24.10.0 to 24.10.15, and 25.10.0 to 25.10.2.
What kind of information can be disclosed due to CVE-2025-12519?
CVE-2025-12519 allows unauthorized access to sensitive information such as downtime or acknowledgement configurations.
Is there a workaround for CVE-2025-12519 while waiting for a patch?
Currently, it is recommended to restrict access to the API endpoint manually until an official patch is applied.