CVE-2024-27930: Sensitive fields access through dropdowns in GLPI
Published Mar 18, 2024
·Updated
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=0.78<10.0.13
Remediation
Event History
Mar 18, 2024
CVE Published
via MITRE·03:29 PM
Data Sourced
via MITRE·03:29 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27930?
The severity of CVE-2024-27930 is determined by its potential impact on sensitive data access by authenticated users.
2
How do I fix CVE-2024-27930?
To fix CVE-2024-27930, upgrade GLPI to version 10.0.13 or later.
3
Who is affected by CVE-2024-27930?
CVE-2024-27930 affects authenticated users of GLPI versions prior to 10.0.13.
4
What type of vulnerability is CVE-2024-27930?
CVE-2024-27930 is a data exposure vulnerability that allows access to sensitive fields data.
5
What versions are vulnerable to CVE-2024-27930?
Versions of GLPI from 0.78 to 10.0.12 are vulnerable to CVE-2024-27930.