CVE-2019-17642: Cross-Site Request Forgery (CSRF)
(updated )
The Autodiscovery plugin of Centreon allows CSRF with remote command execution via shell metacharacters through a POST request to centreon-autodiscovery-server/views/scan/ajax/call.php
.
References
Detect and mitigate CVE-2019-17642 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →