Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j876-75h4-8xcg

Опубликовано: 13 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 4.9

Описание

Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.

This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.

Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.

This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.

EPSS

Процентиль: 6%
0.00024
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-269
CWE-755

Связанные уязвимости

CVSS3: 4.9
nvd
9 месяцев назад

Improper Handling of Exceptional Conditions vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.

EPSS

Процентиль: 6%
0.00024
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-269
CWE-755