Discover the security vulnerability in Centreon versions before 18.10.8, 19.04.5, and 19.10.2 allowing unauthorized access to sensitive data. Learn how to mitigate and prevent this issue.
A vulnerability has been found in Centreon versions prior to 18.10.8, 19.04.5, and 19.10.2 that exposes sensitive information through an unauthorized direct request to api/external.php?object=centreon_metric&action=listByService.
Understanding CVE-2019-17646
This CVE identifies a security issue in Centreon versions before 18.10.8, 19.04.5, and 19.10.2 that could lead to the exposure of sensitive information.
What is CVE-2019-17646?
CVE-2019-17646 is a vulnerability in Centreon software that allows unauthorized access to sensitive information via a specific API request.
The Impact of CVE-2019-17646
The vulnerability could result in the exposure of critical data to unauthorized users, potentially leading to privacy breaches and unauthorized access.
Technical Details of CVE-2019-17646
This section provides more in-depth technical details about the CVE.
Vulnerability Description
The issue in Centreon versions prior to 18.10.8, 19.04.5, and 19.10.2 allows for the disclosure of sensitive information through an unauthenticated direct request.
Affected Systems and Versions
Exploitation Mechanism
The vulnerability can be exploited by sending a specific unauthorized request to the API endpoint api/external.php?object=centreon_metric&action=listByService.
Mitigation and Prevention
Protect your systems from CVE-2019-17646 with the following steps:
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates