Skip to main content

  

Publication date: March 10th, 2025

Component: centreon-web (on central server).

Feature: API Token

 

Description: On the API token page a user with high privilege is able to create an API token for an admin owner and copy this token's value.

 

ReferenceCVE-2024-55572

CVSS7.2 - CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H 

SeverityHIGH

 

Status: Fixes have been provided for all supported versions having this feature and it is recommended to update Centreon Central server:

These versions include cumulative fixes from prior updates.

 

Reporter: Floerer from YesWeHack

Submission: November 25, 2024
 

Stay ahead of potential threats by subscribing to the Security Bulletin section. You’ll receive instant notifications whenever a new bulletin is published, ensuring your infrastructure remains secure and up to date.

Be the first to reply!

Reply