CVE-2025-4649: ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.
Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation.
ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-4649?
The severity of CVE-2025-4649 is categorized as medium.
How do I fix CVE-2025-4649?
To fix CVE-2025-4649, upgrade Centreon web to version 24.10.4 or later.
What does CVE-2025-4649 affect?
CVE-2025-4649 affects Centreon web versions 24.10.3 through 24.10.4, along with earlier versions in the 24.04 and 23.10 series.
What is the impact of CVE-2025-4649?
CVE-2025-4649 allows for improper privilege management leading to privilege escalation on the event logs page.
How does CVE-2025-4649 operate?
CVE-2025-4649 exploits the failure of access control lists to properly restrict log visibility based on user privileges.