In Centreon Web through 2.8.29, disclosure of external components passwords allows authenticated attackers to move laterally to external components.
The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Centreon_web | Centreon | * | 2.8.29 (including) |