First published: Wed Jul 27 2011(Updated: )
It was found that GLPI, the Information Resource-Manager with an additional Administration-Interface, did not properly blacklist certain sensitive variables (like GLPI username and password). A remote attacker could use this flaw to obtain access to plaintext form of these values via specially-crafted HTTP POST request. References: [1] <a href="http://www.glpi-project.org/spip.php?page=annonce&id_breve=237&lang=en">http://www.glpi-project.org/spip.php?page=annonce&id_breve=237&lang=en</a> [2] <a href="https://forge.indepnet.net/projects/glpi/versions/605">https://forge.indepnet.net/projects/glpi/versions/605</a> [3] <a href="https://forge.indepnet.net/issues/3017">https://forge.indepnet.net/issues/3017</a> Relevant patches: [4] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14951">https://forge.indepnet.net/projects/glpi/repository/revisions/14951</a> [5] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14952">https://forge.indepnet.net/projects/glpi/repository/revisions/14952</a> [6] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14954">https://forge.indepnet.net/projects/glpi/repository/revisions/14954</a> [7] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14955">https://forge.indepnet.net/projects/glpi/repository/revisions/14955</a> [8] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14956">https://forge.indepnet.net/projects/glpi/repository/revisions/14956</a> [9] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14957">https://forge.indepnet.net/projects/glpi/repository/revisions/14957</a> [10] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14958">https://forge.indepnet.net/projects/glpi/repository/revisions/14958</a> [11] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14960">https://forge.indepnet.net/projects/glpi/repository/revisions/14960</a> [12] <a href="https://forge.indepnet.net/projects/glpi/repository/revisions/14966">https://forge.indepnet.net/projects/glpi/repository/revisions/14966</a>
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI-PROJECT GLPI | <=0.80.1 | |
GLPI-PROJECT GLPI | =0.5 | |
GLPI-PROJECT GLPI | =0.5-rc1 | |
GLPI-PROJECT GLPI | =0.5-rc2 | |
GLPI-PROJECT GLPI | =0.6 | |
GLPI-PROJECT GLPI | =0.6-rc1 | |
GLPI-PROJECT GLPI | =0.6-rc2 | |
GLPI-PROJECT GLPI | =0.6-rc3 | |
GLPI-PROJECT GLPI | =0.42 | |
GLPI-PROJECT GLPI | =0.51 | |
GLPI-PROJECT GLPI | =0.51a | |
GLPI-PROJECT GLPI | =0.65 | |
GLPI-PROJECT GLPI | =0.65-rc1 | |
GLPI-PROJECT GLPI | =0.65-rc2 | |
GLPI-PROJECT GLPI | =0.68 | |
GLPI-PROJECT GLPI | =0.68-rc1 | |
GLPI-PROJECT GLPI | =0.68-rc2 | |
GLPI-PROJECT GLPI | =0.68-rc3 | |
GLPI-PROJECT GLPI | =0.68.1 | |
GLPI-PROJECT GLPI | =0.68.2 | |
GLPI-PROJECT GLPI | =0.68.3 | |
GLPI-PROJECT GLPI | =0.70 | |
GLPI-PROJECT GLPI | =0.70-rc1 | |
GLPI-PROJECT GLPI | =0.70-rc2 | |
GLPI-PROJECT GLPI | =0.70-rc3 | |
GLPI-PROJECT GLPI | =0.70.1 | |
GLPI-PROJECT GLPI | =0.70.2 | |
GLPI-PROJECT GLPI | =0.71 | |
GLPI-PROJECT GLPI | =0.71.1 | |
GLPI-PROJECT GLPI | =0.71.1-rc1 | |
GLPI-PROJECT GLPI | =0.71.1-rc2 | |
GLPI-PROJECT GLPI | =0.71.1-rc3 | |
GLPI-PROJECT GLPI | =0.71.2 | |
GLPI-PROJECT GLPI | =0.71.3 | |
GLPI-PROJECT GLPI | =0.71.4 | |
GLPI-PROJECT GLPI | =0.71.5 | |
GLPI-PROJECT GLPI | =0.71.6 | |
GLPI-PROJECT GLPI | =0.72 | |
GLPI-PROJECT GLPI | =0.72-rc1 | |
GLPI-PROJECT GLPI | =0.72-rc2 | |
GLPI-PROJECT GLPI | =0.72-rc3 | |
GLPI-PROJECT GLPI | =0.72.1 | |
GLPI-PROJECT GLPI | =0.72.2 | |
GLPI-PROJECT GLPI | =0.72.3 | |
GLPI-PROJECT GLPI | =0.72.4 | |
GLPI-PROJECT GLPI | =0.78 | |
GLPI-PROJECT GLPI | =0.78.1 | |
GLPI-PROJECT GLPI | =0.78.2 | |
GLPI-PROJECT GLPI | =0.78.3 | |
GLPI-PROJECT GLPI | =0.78.4 | |
GLPI-PROJECT GLPI | =0.78.5 | |
GLPI-PROJECT GLPI | =0.80 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.