vendor:
Centreon
by:
Fabien AUNAY, Omri Baso
8.8
CVSS
HIGH
Database Credentials Disclosure
522
CWE
Product Name: Centreon
Affected Version From: 19.10.5
Affected Version To: 19.10.5
Patch Exists: NO
Related CWE: -
CPE: centreon
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: CentOS 7
2020
Centreon 19.10.5 – Database Credentials Disclosure
It is possible to discover the unencrypted password with the inspector.
Mitigation:
Ensure that the database credentials are encrypted and not exposed in plain text.