CVE-2021-39209: Bypassable CSRF protection
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, a user who is logged in to GLPI can bypass Cross-Site Request Forgery (CSRF) protection in many places. This could allow a malicious actor to perform many actions on GLPI. This issue is fixed in version 9.5.6. There are no workarounds aside from upgrading.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 9.5.6
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39209?
CVE-2021-39209 is considered a moderate severity vulnerability due to the potential for unauthorized actions within GLPI.
How do I fix CVE-2021-39209?
To fix CVE-2021-39209, update GLPI to version 9.5.6 or later, where the vulnerability has been patched.
What are the consequences of exploiting CVE-2021-39209?
Exploiting CVE-2021-39209 could allow a malicious user to bypass CSRF protections and perform unauthorized actions on the GLPI system.
Which versions of GLPI are affected by CVE-2021-39209?
All versions of GLPI prior to 9.5.6 are affected by CVE-2021-39209.
Is CVE-2021-39209 a Cross-Site Request Forgery vulnerability?
Yes, CVE-2021-39209 is a vulnerability that allows CSRF protection to be bypassed.