An issue was discovered in Centreon before 2.8-30, 18.10-8, 19.04-5, and 19.10-2.. It provides sensitive information via an unauthenticated direct request for include/configuration/configObject/host/refreshMacroAjax.php.
| Software | From | Fixed in |
|---|---|---|
| centreon / centreon | - | 2.8.30 |
| centreon / centreon | 19.0.0 | 19.04.5 |
| centreon / centreon | 19.04.6 | 19.10.2 |
| centreon / centreon | 2.8.4 | 18.10.8 |