An issue was discovered in Centreon Web through 19.04.3. When a user changes his password on his profile page, the contact_autologin_key field in the database becomes blank when it should be NULL. This makes it possible to partially bypass authentication.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2020-02-24T12:55:57
Updated: 2024-08-05T00:42:03.770Z
Reserved: 2019-08-21T00:00:00
Link: CVE-2019-15299
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-02-24T13:15:11.387
Modified: 2024-11-21T04:28:24.590
Link: CVE-2019-15299
Redhat
No data.