Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.
History

Tue, 13 May 2025 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 13 May 2025 12:00:00 +0000

Type Values Removed Values Added
Description Improper Privilege Management vulnerability in Centreon web allows Privilege Escalation. ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs. This issue affects web: from 24.10.3 before 24.10.4, from 24.04.09 before 24.04.10, from 23.10.19 before 23.10.21, from 23.04.24 before 23.04.26.
Title ACL are not correctly taken into account in the display of the "event logs" page. This page requiring, high privileges, will display all available logs.
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Centreon

Published: 2025-05-13T11:40:23.198Z

Updated: 2025-05-13T13:04:49.906Z

Reserved: 2025-05-13T09:47:58.210Z

Link: CVE-2025-4649

cve-icon Vulnrichment

Updated: 2025-05-13T13:04:43.180Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-05-13T12:15:18.047

Modified: 2025-05-13T19:35:18.080

Link: CVE-2025-4649

cve-icon Redhat

No data.