4.3

CVE-2020-10945

Centreon before 19.10.7 exposes Session IDs in server responses.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CentreonCentreon Version <= 2.8.2
CentreonCentreon Version >= 18.10.0 < 18.10.11
CentreonCentreon Version >= 19.04.0 < 19.04.10
CentreonCentreon Version >= 19.10 < 19.10.7
CentreonWidget-host-monitoring Version < 1.6.4
CentreonWidget-host-monitoring Version >= 18.10.0 < 18.10.3
CentreonWidget-host-monitoring Version >= 19.04.0 < 19.04.3
CentreonWidget-host-monitoring Version19.10.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.126
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 2.8 1.4
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 3.3 6.5 2.9
AV:A/AC:L/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.