CVE-2023-34107: GLPI vulnerable to unauthorized access to KnowbaseItem data
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
GLPIto a version that resolves this vulnerability.Fixed in 10.0.8
Event History
Frequently Asked Questions
What is CVE-2023-34107?
CVE-2023-34107 is a vulnerability in the GLPI software that allows an authenticated user to access the view all KnowbaseItems.
What is the severity of CVE-2023-34107?
The severity of CVE-2023-34107 is medium with a CVSS score of 6.5.
Which versions of GLPI are affected by CVE-2023-34107?
Versions of GLPI starting from 9.2.0 and prior to 10.0.8 are affected by CVE-2023-34107.
How can an attacker exploit CVE-2023-34107?
An attacker can exploit CVE-2023-34107 by being an authenticated user and accessing a file with incorrect rights check, allowing them to view all KnowbaseItems.
How can I fix CVE-2023-34107?
To fix CVE-2023-34107, update GLPI to version 10.0.8, which contains a patch for this vulnerability.