QID 994844
Date Published: 2023-08-14
QID 994844: PHP (Composer) Security Update for centreon/centreon (GHSA-c4fj-3wqq-g9c9)
The escape_command function in include/Administration/corePerformance/getStats.php in Centreon (formerly Merethis Centreon) 2.5.4 and earlier (offending file deleted in Centreon 19.10.0) uses an incorrect regular expression, which allows remote authenticated users to execute arbitrary commands via shell metacharacters in the ns_id parameter.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-c4fj-3wqq-g9c9 for updates and patch information.
Vendor References
- GHSA-c4fj-3wqq-g9c9 -
github.com/advisories/GHSA-c4fj-3wqq-g9c9
CVEs related to QID 994844
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c4fj-3wqq-g9c9 | centreon/centreon |
|