漏洞信息详情
Centreon SQL注入漏洞
漏洞简介
Centreon(Merethis Centreon)是法国Centreon公司的一套开源的系统监控工具 。该产品主要提供对网络、系统和应用程序等资源的监控功能。
Centreon中存在SQL注入漏洞。攻击者可通过发送特制SQL语句到include/monitoring/status/Hosts/xml/hostXML.php脚本利用该漏洞查看、添加、修改或删除后台信息。以下产品及版本受到影响:Centreon 2.8.30之前版本,18.10.8之前版本,19.04.5之前版本,19.10.2之前版本。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://documentation.centreon.com/docs/centreon/zh-CN/latest/release_notes/centreon-18.10.html#centreon-web-18-10-8
https://documentation.centreon.com/docs/centreon/zh-CN/latest/release_notes/centreon-19.04.html#centreon-web-19-04-5
https://documentation.centreon.com/docs/centreon/zh-CN/latest/release_notes/centreon-19.10.html#centreon-web-19-10-2
https://documentation.centreon.com/docs/centreon/zh-CN/latest/release_notes/centreon-2.8.html#centreon-web-2-8-30
参考网址
来源:CONFIRM
链接:https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10.html#centreon-web-19-10-2
来源:CONFIRM
链接:https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.04.html#centreon-web-19-04-5
来源:CONFIRM
链接:https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-18.10.html#centreon-web-18-10-8
来源:MISC
链接:https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-19.10/index.html
来源:CONFIRM
链接:https://documentation.centreon.com/docs/centreon/en/latest/release_notes/centreon-2.8.html#centreon-web-2-8-30
来源:CONFIRM
链接:https://github.com/centreon/centreon/pull/8063
来源:nvd.nist.gov
链接:https://nvd.nist.gov/vuln/detail/CVE-2019-17647
受影响实体
暂无
补丁
- Centreon SQL注入漏洞的修复措施<!--2020-3-5-->
还没有评论,来说两句吧...