Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c4fj-3wqq-g9c9

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.5

Описание

Centreon Command Injection

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (offending file deleted in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.

Пакеты

Наименование

centreon/centreon

composer
Затронутые версииВерсия исправления

< 2.8.28

2.8.28

EPSS

Процентиль: 90%
0.05236
Низкий

8.5 High

CVSS3

Дефекты

CWE-77

Связанные уязвимости

nvd
больше 10 лет назад

The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (fixed in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.

EPSS

Процентиль: 90%
0.05236
Низкий

8.5 High

CVSS3

Дефекты

CWE-77