CVE-2020-22345
Description
Remote attackers can execute arbitrary OS commands in Centreon 19.10.8 via shell metacharacters in the RRDdatabase_path parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Remote attackers can execute arbitrary OS commands in Centreon 19.10.8 via shell metacharacters in the RRDdatabase_path parameter.
Vulnerability
The vulnerability exists in Centreon version 19.10.8 in the file /graphStatus/displayServiceStatus.php. The RRDdatabase_path parameter is not sanitized, allowing an attacker to inject shell metacharacters, leading to OS command injection [2].
Exploitation
An attacker can send a crafted HTTP request to the vulnerable endpoint with malicious shell metacharacters in the RRDdatabase_path parameter. No authentication is required, making it remotely exploitable [2].
Impact
Successful exploitation allows arbitrary OS command execution on the server. The attacker can execute system commands with the privileges of the web server, potentially leading to full compromise of the monitoring server and access to sensitive data.
Mitigation
A fix has been proposed in a pull request [1]. Users should upgrade to a patched version of Centreon once available. As of the publication date, no official release with the fix is mentioned, but updating to the latest version is recommended. If immediate upgrade is not possible, restrict access to the vulnerable endpoint.
AI Insight generated on May 21, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
centreon/centreonPackagist | < 20.04.0 | 20.04.0 |
Affected products
2- Centreon/Centreondescription
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- github.com/advisories/GHSA-2q95-593f-g7h7ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-22345ghsaADVISORY
- engindemirbilek.github.io/centreon-19.10-rceghsax_refsource_MISCWEB
- github.com/centreon/centreon/pull/8467ghsax_refsource_MISCWEB
News mentions
0No linked articles in our index yet.