Authentication Bypass by Capture-replay in Centreon - #VU50439
Published: February 9, 2021
Centreon
Centreon
Description
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to Centreon uses tokens vulnerable to replay attacks. A remote attacker with ability to intercept authentication token can re-use it in order to authenticate against the application.
Also the mandatory token usage was addressed by the vendor.