First published: Wed Jul 05 2023(Updated: )
GLPI is a free asset and IT management software package. Versions of the software starting with 9.2.0 and prior to 10.0.8 have an incorrect rights check on a on a file accessible by an authenticated user, allows access to the view all KnowbaseItems. Version 10.0.8 has a patch for this issue.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI-PROJECT GLPI | >=9.2.0<10.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34107 is a vulnerability in the GLPI software that allows an authenticated user to access the view all KnowbaseItems.
The severity of CVE-2023-34107 is medium with a CVSS score of 6.5.
Versions of GLPI starting from 9.2.0 and prior to 10.0.8 are affected by CVE-2023-34107.
An attacker can exploit CVE-2023-34107 by being an authenticated user and accessing a file with incorrect rights check, allowing them to view all KnowbaseItems.
To fix CVE-2023-34107, update GLPI to version 10.0.8, which contains a patch for this vulnerability.