First published: Wed Oct 07 2020(Updated: )
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Teclib GLPI | >=9.5.0<9.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-15217 is considered a medium severity vulnerability due to the leakage of user information.
To fix CVE-2020-15217, upgrade to GLPI version 9.5.2 or later.
CVE-2020-15217 affects GLPI versions prior to 9.5.2, specifically version 9.5.0.
CVE-2020-15217 was introduced due to a change in the public FAQ feature in GLPI version 9.5.0.
Yes, a workaround for CVE-2020-15217 is to disable public access to the FAQ.