Centreon Web 19.04.4 has weak permissions within the OVA (aka VMware virtual machine) and OVF (aka VirtualBox virtual machine) files, allowing attackers to gain privileges via a Trojan horse Centreon-autodisco executable file that is launched by cron.
| Software | From | Fixed in |
|---|---|---|
| centreon / centreon_web | 19.04.4 | 19.04.4.x |