CVE-2021-39213: IP restriction on GLPI API Bypass with custom header injection
GLPI is a free Asset and IT management software package. Starting in version 9.1 and prior to version 9.5.6, GLPI with API Rest enabled is vulnerable to API bypass with custom header injection. This issue is fixed in version 9.5.6. One may disable API Rest as a workaround.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 9.5.6 - Configuration
Disable GLPI REST API as a workaround when running versions starting in 9.1 and prior to 9.5.6.
GLPI (API Rest) API Rest = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39213?
CVE-2021-39213 has been classified as a moderate severity vulnerability.
How do I fix CVE-2021-39213?
To fix CVE-2021-39213, upgrade GLPI to version 9.5.6 or disable the API Rest feature.
What versions of GLPI are affected by CVE-2021-39213?
GLPI versions starting from 9.1 to prior 9.5.6 are affected by CVE-2021-39213.
What type of vulnerability is CVE-2021-39213?
CVE-2021-39213 is an API bypass vulnerability with custom header injection.
Is there a workaround for CVE-2021-39213?
Yes, a temporary workaround for CVE-2021-39213 is to disable the API Rest feature.