CVE-2022-31068: Sensitive Data Exposure on Refused Inventory Files in GLPI
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. In affected versions all GLPI instances with the native inventory used may leak sensitive information. The feature to get refused file is not authenticated. This issue has been addressed in version 10.0.2 and all affected users are advised to upgrade.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-31068?
CVE-2022-31068 is a vulnerability in the GLPI software that can lead to the leakage of sensitive information.
What is the severity of CVE-2022-31068?
The severity of CVE-2022-31068 is medium with a CVSS score of 5.3.
Which versions of GLPI are affected by CVE-2022-31068?
Versions 10.0.0 to 10.0.2 of GLPI are affected by CVE-2022-31068.
How can CVE-2022-31068 be exploited?
CVE-2022-31068 can be exploited by unauthorized attackers who have access to GLPI instances with the native inventory feature enabled.
Is there a fix for CVE-2022-31068?
Yes, a fix for CVE-2022-31068 is available. It is recommended to update GLPI to a version beyond 10.0.2.