Miggo Logo

CVE-2021-28055:
Predictable CSRF tokens in centreon/centreon

6.5

CVSS Score
3.1

Basic Information

EPSS Score
0.25739%
Published
6/8/2021
Updated
1/27/2023
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Package NameEcosystemVulnerable VersionsFirst Patched Version
centreon/centreoncomposer>= 20.10.0, < 20.10.720.10.7
centreon/centreoncomposer>= 20.04.0, < 20.04.1320.04.13
centreon/centreoncomposer>= 19.10.0, < 19.10.2319.10.23
centreon/centreoncomposer< 2.8.372.8.37

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis

While the exact commit diff is unavailable, the vulnerability description explicitly points to predictable CSRF token generation. In PHP applications, CSRF tokens are typically generated in security-related utility classes. The confidence is medium because: 1) The CWE-330 directly implicates random value generation functions 2) The patch would logically target the token generation mechanism 3) Centreon's architecture likely centralizes CSRF handling in security modules. However, without seeing the actual pre-patch code, this remains an inference based on vulnerability patterns.

Vulnerable functions

Only Mi**o us*rs **n s** t*is s**tion

WAF Protection Rules

WAF Rule

*n issu* w*s *is*ov*r** in **ntr*on-W** in **ntr*on Pl*t*orm **.**.*. T** *nti-*SR* tok*n **n*r*tion is pr**i*t**l*, w*i** mi**t *llow *SR* *tt**ks t**t *** *n **min us*r.

Reasoning

W*il* t** *x**t *ommit *i** is un*v*il**l*, t** vuln*r**ility **s*ription *xpli*itly points to pr**i*t**l* *SR* tok*n **n*r*tion. In `P*P` *ppli**tions, *SR* tok*ns *r* typi**lly **n*r*t** in s**urity-r*l*t** utility *l*ss*s. T** *on*i**n** is m**ium