CVE-2022-24867: LDAP password exposure in glpi
GLPI is a Free Asset and IT Management Software package, that provides ITIL Service Desk features, licenses tracking and software auditing. When you pass the config to the javascript, some entries are filtered out. The variable ldappass is not filtered and when you look at the source code of the rendered page, we can see the password for the root dn. Users are advised to upgrade. There is no known workaround for this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-24867?
CVE-2022-24867 has a medium severity rating due to the potential exposure of sensitive data.
How do I fix CVE-2022-24867?
To fix CVE-2022-24867, update GLPI to version 10.0.0 or later where the vulnerability has been addressed.
What versions of GLPI are affected by CVE-2022-24867?
GLPI versions prior to 10.0.0 are affected by CVE-2022-24867.
What type of vulnerability is CVE-2022-24867?
CVE-2022-24867 is a data exposure vulnerability that potentially leaks sensitive configuration information.
Who can be impacted by CVE-2022-24867?
Users of GLPI versions prior to 10.0.0 can be impacted by CVE-2022-24867 if they are using configurations that lead to sensitive information being exposed.