First published: Tue Jun 28 2022(Updated: )
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is not authenticated. This issue has been addressed in version 10.0.2 and all affected users are advised to upgrade.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI-PROJECT GLPI | >=10.0.0<10.0.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31068 is a vulnerability in the GLPI software that can lead to the leakage of sensitive information.
The severity of CVE-2022-31068 is medium with a CVSS score of 5.3.
Versions 10.0.0 to 10.0.2 of GLPI are affected by CVE-2022-31068.
CVE-2022-31068 can be exploited by unauthorized attackers who have access to GLPI instances with the native inventory feature enabled.
Yes, a fix for CVE-2022-31068 is available. It is recommended to update GLPI to a version beyond 10.0.2.