CVE-2011-2720: Infoleak
It was found that GLPI, the Information Resource-Manager with an additional Administration-Interface, did not properly blacklist certain sensitive variables (like GLPI username and password). A remote attacker could use this flaw to obtain access to plaintext form of these values via specially-crafted HTTP POST request.
References: [1] http://www.glpi-project.org/spip.php?page=annonce&idbreve=237&lang=en [2] https://forge.indepnet.net/projects/glpi/versions/605 [3] https://forge.indepnet.net/issues/3017
Relevant patches: [4] https://forge.indepnet.net/projects/glpi/repository/revisions/14951 [5] https://forge.indepnet.net/projects/glpi/repository/revisions/14952 [6] https://forge.indepnet.net/projects/glpi/repository/revisions/14954 [7] https://forge.indepnet.net/projects/glpi/repository/revisions/14955 [8] https://forge.indepnet.net/projects/glpi/repository/revisions/14956 [9] https://forge.indepnet.net/projects/glpi/repository/revisions/14957 [10] https://forge.indepnet.net/projects/glpi/repository/revisions/14958 [11] https://forge.indepnet.net/projects/glpi/repository/revisions/14960 [12] https://forge.indepnet.net/projects/glpi/repository/revisions/14966
Other sources
The autocompletion functionality in GLPI before 0.80.2 does not blacklist certain username and password fields, which allows remote attackers to obtain sensitive information via a crafted POST request.
— MITRE
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-2720?
CVE-2011-2720 is considered to be a medium severity vulnerability due to its potential exposure of sensitive information.
How do I fix CVE-2011-2720?
To fix CVE-2011-2720, upgrade GLPI to a version later than 0.80.1, which addresses the sensitive variable blacklisting issue.
What does CVE-2011-2720 affect?
CVE-2011-2720 affects multiple versions of GLPI, specifically versions up to and including 0.80.1.
Can CVE-2011-2720 allow unauthorized access?
Yes, CVE-2011-2720 can allow remote attackers to access sensitive GLPI credentials in plaintext.
Is there a specific GLPI version that is vulnerable to CVE-2011-2720?
Yes, CVE-2011-2720 affects GLPI versions from 0.5 to 0.80.1, inclusive.