CVE-2021-39210: Autologin cookie accessible by scripts
GLPI is a free Asset and IT management software package. In versions prior to 9.5.6, the cookie used to store the autologin cookie (when a user uses the "remember me" feature) is accessible by scripts. A malicious plugin that could steal this cookie would be able to use it to autologin. This issue is fixed in version 9.5.6. As a workaround, one may avoid using the "remember me" feature.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 9.5.6 - Configuration
Workaround: avoid using the "remember me" feature to prevent use of the vulnerable autologin cookie (issue affects GLPI versions prior to 9.5.6).
GLPI remember me feature = disable
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39210?
CVE-2021-39210 is classified as a medium severity vulnerability due to the risk of cookie theft enabling unauthorized access.
How do I fix CVE-2021-39210?
To fix CVE-2021-39210, upgrade GLPI to version 9.5.6 or later to mitigate the risk associated with the exposed autologin cookie.
What versions are affected by CVE-2021-39210?
CVE-2021-39210 affects all GLPI versions prior to 9.5.6.
What is the impact of CVE-2021-39210 on user security?
The impact of CVE-2021-39210 allows an attacker to potentially gain unauthorized access by stealing users' autologin cookies if they exploit the vulnerability.
Is CVE-2021-39210 related to script accessibility?
Yes, CVE-2021-39210 involves a vulnerability where the autologin cookie is accessible by scripts, making it exploitable by malicious plugins.