-
CVSS Score
-The vulnerability stems from improper command-line argument construction in centreonGraph.class.php. The commit diff shows the fix added escapeshellarg() to user-controlled values in the displayImageFlow() method when building the RRDtool command. Prior to this fix, RPN values from Virtual Metrics were directly concatenated into the command string without sanitization, enabling code injection via crafted RPN expressions. The displayImageFlow() function is directly responsible for executing the vulnerable command chain.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| centreon/centreon | composer | = 3.4.6 | |
| centreon/centreon | composer | = 2.8.23 | 2.8.24 |
A Semantic Attack on Google Gemini - Read the Latest Research