Описание
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
Ссылки
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- PatchThird Party Advisory
- Release NotesVendor Advisory
- Release NotesVendor Advisory
- PatchThird Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 19.04.3 (включая)
cpe:2.3:a:centreon:centreon_web:*:*:*:*:*:*:*:*
EPSS
Процентиль: 19%
0.0006
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-287
Связанные уязвимости
github
больше 3 лет назад
An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
EPSS
Процентиль: 19%
0.0006
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-287