Описание
Centreon RCE Vulnerability
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2018-11587
- https://github.com/centreon/centreon-archived/pull/6263
- https://github.com/centreon/centreon-archived/pull/6263/commits/fb438e6aaf133cc5f9d25130653ba8fdc6ecf51f
- https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8/centreon-2.8.24.html
Пакеты
Наименование
centreon/centreon
composer
Затронутые версииВерсия исправления
= 3.4.6
Отсутствует
Наименование
centreon/centreon
composer
Затронутые версииВерсия исправления
= 2.8.23
2.8.24
Связанные уязвимости
CVSS3: 9.8
nvd
больше 7 лет назад
There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.