An issue was discovered in Centreon before 18.10.8, 19.04.5, and 19.10.2. It provides sensitive information via an unauthenticated direct request for api/external.php?object=centreon_metric&action=listByService.
| Software | From | Fixed in |
|---|---|---|
| centreon / centreon | 18.0.0 | 18.10.8 |
| centreon / centreon | 19.04.0 | 19.04.5 |
| centreon / centreon | 19.10.0 | 19.10.2 |