CVE-2024-27937: glpi Users emails enumeration
Published Mar 18, 2024
·Updated
GLPI is a Free Asset and IT Management Software package, Data center management, ITIL Service Desk, licenses tracking and software auditing. An authenticated user can obtain the email address of all GLPI users. This issue has been patched in version 10.0.13.
Affected Software
1 affected component
GLPI-PROJECT GLPI>=10.0.0<10.0.13
Remediation
Event History
Mar 18, 2024
CVE Published
via MITRE·03:17 PM
Data Sourced
via MITRE·03:17 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-27937?
CVE-2024-27937 has been classified with a moderate severity as it allows an authenticated user to access sensitive user information.
2
How do I fix CVE-2024-27937?
To fix CVE-2024-27937, upgrade to GLPI version 10.0.13 or later.
3
Who is affected by CVE-2024-27937?
All users of GLPI versions from 10.0.0 to 10.0.12 are affected by CVE-2024-27937.
4
What information can be exposed due to CVE-2024-27937?
CVE-2024-27937 allows an authenticated user to obtain the email addresses of all GLPI users.
5
Is there a patch available for CVE-2024-27937?
Yes, a patch for CVE-2024-27937 is included in GLPI version 10.0.13.