CVE-2023-34106: GLPI vulnerable to unauthorized access to User data
GLPI is a free asset and IT management software package. Versions of the software starting with 0.68 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user. This allows access to the list of all users and their personal information. Users should upgrade to version 10.0.8 to receive a patch.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.8 - Compensating control
For GLPI versions starting with 0.68 and prior to 10.0.8, mitigate unauthorized access by restricting authenticated access to the affected file that has an incorrect rights check (until upgrading to 10.0.8).
Event History
Frequently Asked Questions
What is the vulnerability ID for this GLPI vulnerability?
The vulnerability ID for this GLPI vulnerability is CVE-2023-34106.
What is GLPI?
GLPI is a free asset and IT management software package.
What is the severity of CVE-2023-34106?
The severity of CVE-2023-34106 is medium with a CVSS score of 6.5.
How does CVE-2023-34106 affect GLPI?
CVE-2023-34106 allows an authenticated user to access the list of all users and their personal information in versions of GLPI prior to 10.0.8.
How can I fix CVE-2023-34106?
To fix CVE-2023-34106, users should upgrade their GLPI software to version 10.0.8 or later.