Incorrect Default Permissions in Centreon Infra Monitoring Affects Multiple Versions
CVE-2025-8432
8.4HIGH
What is CVE-2025-8432?
The Centreon Infra Monitoring software faces a significant security issue due to incorrect default permissions in its MBI modules. This vulnerability allows users with a CentreonBI account to embed scripts within scripts on the MBI server, potentially leading to unauthorized access and manipulation of sensitive data. Versions affected include 24.10.0 to 24.10.5, 24.04.0 to 24.04.8, and 23.10.0 to 23.10.14. It is crucial for users to apply the necessary updates to mitigate these risks.
Affected Version(s)
Infra Monitoring 24.10.0 < 24.10.6
Infra Monitoring 24.04.0 < 24.04.9
Infra Monitoring 23.10.0 < 23.10.15
