An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Centreon | Centreon | 18.0.0 (including) | 18.10.8 (excluding) |
Centreon | Centreon | 19.04.0 (including) | 19.04.5 (excluding) |
Centreon | Centreon | 19.10.0 (including) | 19.10.2 (excluding) |