CVE-2024-27937

medium

Description

GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13.

References

https://github.com/glpi-project/glpi/security/advisories/GHSA-98qw-hpg3-2hpj

https://github.com/glpi-project/glpi/releases/tag/10.0.13

https://github.com/glpi-project/glpi/commit/d02c537d23cbb729fe18b87f71b3c6e84e9892da

https://borelenzo.github.io/stuff/2024/02/29/glpi-pwned.html

Details

Source: Mitre, NVD

Published: 2024-03-18

Updated: 2024-04-24

Risk Information

CVSS v2

Base Score: 6.4

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Severity: Medium