5
CVSSv2

CVE-2018-21020

Published: 08/10/2019 Updated: 11/10/2019
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

In very rare cases, a PHP type juggling vulnerability in centreonAuth.class.php in Centreon Web prior to 2.8.27 allows malicious users to bypass authentication mechanisms in place.

Vulnerability Trend

Affected Products

Vendor Product Versions
CentreonCentreon Web2.4, 2.4.1, 2.4.4, 2.4.5, 2.5, 2.5.1, 2.5.2, 2.5.3, 2.5.4, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.7.0, 2.7.1, 2.7.2, 2.7.3, 2.7.4, 2.7.5, 2.7.6, 2.7.7, 2.7.8, 2.7.9, 2.7.10, 2.7.11, 2.7.12, 2.8, 2.8.1, 2.8.2, 2.8.3, 2.8.4, 2.8.5, 2.8.6, 2.8.7, 2.8.8, 2.8.9, 2.8.10, 2.8.11, 2.8.12, 2.8.13, 2.8.14, 2.8.15, 2.8.16, 2.8.17, 2.8.18, 2.8.19, 2.8.20, 2.8.21, 2.8.22, 2.8.23, 2.8.24, 2.8.25, 2.8.26

Mailing Lists

Centreon ======== "Centreon is the N°1 Open Source IT Infrastructure Monitoring Solution" Multiple vulnerabilites were discovered in Centreon-Web in december 2018 and fixed in early 2019 over the course of two minor releases on both branches in versions 2827/2828 and 18104/18105 documentationcentreoncom/docs/centreon/en/late ...