CVE-2021-39190: SCCM plugin for GLPI vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
Published Sep 22, 2022
·Updated
The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist.
Affected Software
1 affected component
Teclib-edition System Center Configuration Manager Gpli<2.3.0
Remediation
Event History
Sep 22, 2022
CVE Published
via MITRE·04:30 PM
Data Sourced
via MITRE·04:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-39190.
2
What is the severity of CVE-2021-39190?
The severity of CVE-2021-39190 is medium with a severity value of 5.3.
3
What is the affected software version for CVE-2021-39190?
The affected software version for CVE-2021-39190 is Teclib-edition System Center Configuration Manager up to version 2.3.0 (exclusive).
4
How can I fix CVE-2021-39190?
To fix CVE-2021-39190, update the SCCM plugin for GLPI to version 2.3.0 or later.
5
Are there any known workarounds for CVE-2021-39190?
No, there are no known workarounds for CVE-2021-39190.