GHSA-c8qc-cp8v-prpx

Suggest an improvement
Source
https://github.com/advisories/GHSA-c8qc-cp8v-prpx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-c8qc-cp8v-prpx/GHSA-c8qc-cp8v-prpx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-c8qc-cp8v-prpx
Aliases
  • CVE-2018-11587
Published
2022-05-14T03:02:59Z
Modified
2023-11-08T03:59:46.268739Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Centreon RCE Vulnerability
Details

There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php.

Database specific
{
    "nvd_published_at": "2018-06-25T18:29:00Z",
    "cwe_ids": [
        "CWE-94"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-25T00:06:18Z"
}
References

Affected packages

Packagist / centreon/centreon

Package

Name
centreon/centreon
Purl
pkg:composer/centreon/centreon

Affected ranges

Affected versions

3.*

3.4.6

Packagist / centreon/centreon

Package

Name
centreon/centreon
Purl
pkg:composer/centreon/centreon

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.8.23
Fixed
2.8.24

Affected versions

2.*

2.8.23