CVE-2020-15217: User data exposure in GLPI
Published Oct 7, 2020
·Updated
In GLPI before version 9.5.2, there is a leakage of user information through the public FAQ. The issue was introduced in version 9.5.0 and patched in 9.5.2. As a workaround, disable public access to the FAQ.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=9.5.0<9.5.2
Remediation
Event History
Oct 7, 2020
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2020-15217?
CVE-2020-15217 is considered a medium severity vulnerability due to the leakage of user information.
2
How do I fix CVE-2020-15217?
To fix CVE-2020-15217, upgrade to GLPI version 9.5.2 or later.
3
What does CVE-2020-15217 affect?
CVE-2020-15217 affects GLPI versions prior to 9.5.2, specifically version 9.5.0.
4
How did CVE-2020-15217 happen?
CVE-2020-15217 was introduced due to a change in the public FAQ feature in GLPI version 9.5.0.
5
Is there a workaround for CVE-2020-15217?
Yes, a workaround for CVE-2020-15217 is to disable public access to the FAQ.