Centreon Open Tickets Path Traversal Vulnerability Allowing Arbitrary File Write or Delete
Vulnerability
A path traversal vulnerability has been identified in the Centreon Open Tickets module on Central Server, specifically in Linux environments. This vulnerability affects versions prior to 25.10.3, as well as 24.10.8 and 24.04.7. The issue allows authenticated users to manipulate file uploads, potentially leading to the writing or deletion of arbitrary files on the server.
Impact
Exploitation of this vulnerability could result in unauthorized file manipulation, allowing for the writing or deletion of files on the server.
Remediation
Users are advised to update to Centreon Open Tickets versions 25.10.3, 24.10.8, or 24.04.7. These versions include cumulative fixes from prior updates. Centreon users on a High Availability Platform should follow the Centreon HA Update procedures.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
