First published: Mon Mar 18 2024(Updated: )
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can access sensitive fields data from items on which he has read access. This issue has been patched in version 10.0.13.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
GLPI | >=0.78<10.0.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2024-27930 is determined by its potential impact on sensitive data access by authenticated users.
To fix CVE-2024-27930, upgrade GLPI to version 10.0.13 or later.
CVE-2024-27930 affects authenticated users of GLPI versions prior to 10.0.13.
CVE-2024-27930 is a data exposure vulnerability that allows access to sensitive fields data.
Versions of GLPI from 0.78 to 10.0.12 are vulnerable to CVE-2024-27930.