Fedora 29 : glpi (2019-a66789a334)

high Nessus Plugin ID 123806

Language:

Synopsis

The remote Fedora host is missing a security update.

Description

Add security fix backported from 9.4 :

- [security] Bad chevrons rendering on dropdowns (#5468)

- [security] Iframe and forms are rendered in rich text contents (#5519)

- [security] Type juggling authentication bypass (#5520)

- [security] Malicious images upload (#5580)

- [security] Password token date was not reset (#5577)

- [security] Prevent timed attack and enforce cookie security (#5562)

Note that Tenable Network Security has extracted the preceding description block directly from the Fedora update system website.
Tenable has attempted to automatically clean and format it as much as possible without introducing additional issues.

Solution

Update the affected glpi package.

See Also

https://bodhi.fedoraproject.org/updates/FEDORA-2019-a66789a334

Plugin Details

Severity: High

ID: 123806

File Name: fedora_2019-a66789a334.nasl

Version: 1.2

Type: local

Agent: unix

Published: 4/8/2019

Updated: 9/23/2019

Supported Sensors: Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Nessus

Vulnerability Information

CPE: p-cpe:/a:fedoraproject:fedora:glpi, cpe:/o:fedoraproject:fedora:29

Required KB Items: Host/local_checks_enabled, Host/RedHat/release, Host/RedHat/rpm-list

Patch Publication Date: 4/6/2019

Vulnerability Publication Date: 4/6/2019

Reference Information