Component: centreon-autodiscovery
List of vulnerabilities: 1
Description: Defense-in-depth: parameterized batch insert for rule contact & contactgroup relations
Reference: N/A
CVSS: 0
Severity: Low
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Autodiscovery on Central Server:
Component: centreon-map
List of vulnerabilities: 8
Description: Validate resource ACL on save and gate the editor mx-views endpoints
Reference: N/A
CVSS: 8.1
Severity: High
Description: Remove unauthenticated access-rule endpoints
Reference: N/A
CVSS: 7.1
Severity: High
Description: Move editor metric/graph selection to the standard API
Reference: N/A
CVSS: 6.5
Severity: Medium
Description: Scope geoview resource reads to the geoview
Reference: N/A
CVSS: 6.5
Severity: Medium
Description: Gate the map and geoview import endpoints
Reference: N/A
CVSS: 6.5
Severity: Medium
Description: Scope standard-map resource reads to the map/view
Reference: N/A
CVSS: 6.5
Severity: Medium
Description: Restrict map access-rule assignment on import to the caller's ACL groups
Reference: N/A
CVSS: 4.3
Severity: Medium
Description: Restrict the resource-synchronizer reload endpoint
Reference: N/A
CVSS: 4.3
Severity: Medium
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Map on Central Server:
Component: centreon-mbi
List of vulnerabilities: 3
Description: SQL injection via string concatenation and raw access-group lists (follow-up to MON-195895)
Reference: N/A
CVSS: 8.8
Severity: High
Description: Path traversal via file functions in centreon-bi-server download endpoints
Reference: N/A
CVSS: 6.5
Severity: Medium
Description: XSS via unescaped output in legacy forms/widgets + remove unused dhtmlx library
Reference: N/A
CVSS: 6.1
Severity: Medium
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Mbi on Central Server:
Component: centreon-web
List of vulnerabilities: 4
Description: SQL injection, XSS & disabled TLS verification across legacy PHP files
Reference: N/A
CVSS: 7
Severity: High
Description: Frontend JS / TS (DOM XSS, eval, open redirect, test-only SQLi/path traversal)
Reference: N/A
CVSS: 7
Severity: High
Description: Fix critical issue in robrichards/xmlseclibs
Reference: N/A
CVSS: 7
Severity: High
Description: Defense-in-depth: JS/DOM/SQL output hardening in legacy header, custom-view widget & KB services
Reference: N/A
CVSS: 0
Severity: Low
Status: Fixes have been provided for all supported versions and it is recommended to update Centreon Web on Central Server:
